CVE-2026-5879 is an insufficient input validation vulnerability in the ANGLE graphics library component of Google Chrome on macOS versions prior to 147.0.7727.55. The flaw permits remote attackers to execute arbitrary code within Chrome's sandbox environment through a malicious HTML page, requiring only user interaction to trigger. The vulnerability presents significant risk with a CVSS score of 8.8 (HIGH) and network-based attack vector requiring no special privileges. While executing within a sandbox limits immediate system-wide compromise, the attack succeeds with relatively low complexity and results in high impact across confidentiality, integrity, and availability if the sandbox is circumvented. Exploitation status indicates low current threat activity, with no confirmed public exploits in the wild and an EPSS score of 0.00148 placing this vulnerability well below the median exploitation likelihood. The vulnerability is not tracked on CISA's Known Exploited Vulnerabilities list and shows inactive status on security hotlists, suggesting limited community attention at this time. Organizations should prioritize patching Chrome to version 147.0.7727.55 or later as part of regular update cycles rather than emergency response protocols.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.