Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5879

27
FAUCET Score

CVE-2026-5879 is an insufficient input validation vulnerability in the ANGLE graphics library component of Google Chrome on macOS versions prior to 147.0.7727.55. The flaw permits remote attackers to execute arbitrary code within Chrome's sandbox environment through a malicious HTML page, requiring only user interaction to trigger. The vulnerability presents significant risk with a CVSS score of 8.8 (HIGH) and network-based attack vector requiring no special privileges. While executing within a sandbox limits immediate system-wide compromise, the attack succeeds with relatively low complexity and results in high impact across confidentiality, integrity, and availability if the sandbox is circumvented. Exploitation status indicates low current threat activity, with no confirmed public exploits in the wild and an EPSS score of 0.00148 placing this vulnerability well below the median exploitation likelihood. The vulnerability is not tracked on CISA's Known Exploited Vulnerabilities list and shows inactive status on security hotlists, suggesting limited community attention at this time. Organizations should prioritize patching Chrome to version 147.0.7727.55 or later as part of regular update cycles rather than emergency response protocols.

Impacted Technologies

VendorProductVersion(s)CPE
< 147.0.7727.55CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
>= 147.0.7727.55, < 147.0.7727.55CPE match
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 27th percentile among its peer group of 14,875 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

microsoftpatch availablevia msrc
Product: Microsoft Edge (Chromium-based)Fixed in: 147.0.3912.60

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-5879

Chromium: CVE-2026-5879 Insufficient validation of untrusted input in ANGLE

Apr 2, 2026

References

chromereleases.googleblog.com / 2026/04/stable-channel-update-for-desktop.html
Release NotesVendor Advisory
issues.chromium.org / issues/40073848
Permissions Required