CVE-2026-5885 is a medium-severity vulnerability affecting Google Chrome on Windows versions prior to 147.0.7727.55, involving insufficient validation of untrusted input in the WebML component. This flaw enables remote attackers to extract potentially sensitive information from process memory through a specially crafted HTML page. The vulnerability has a CVSS score of 6.5, reflecting its moderate risk level with a high confidentiality impact but no integrity or availability consequences. The attack vector is network-based with low complexity and requires only user interaction (clicking a malicious link), making it relatively easy to exploit despite not requiring any special privileges. The information disclosure impact is significant, as attackers can access sensitive data stored in process memory, though the vulnerability does not enable system compromise or data modification. The EPSS score of 0.00044 indicates this vulnerability is less likely to be exploited in the wild compared to the overall CVE population. There is no indication of active exploitation in the wild, and the vulnerability has not been added to the Known Exploited Vulnerabilities (KEV) catalog. It remains on an inactive status in security tracking systems, and there is no public exploit code currently available. Organizations should prioritize updating to Chrome 147.0.7727.55 or later to mitigate this risk, particularly for systems handling sensitive information.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.