CVE-2026-5907 is an insufficient data validation vulnerability in the Media component of Google Chrome versions prior to 147.0.7727.55 that allows remote attackers to read out-of-bounds memory by submitting a specially crafted video file. The vulnerability affects Chrome users across all platforms where the browser processes video content. The vulnerability presents a high risk profile with a CVSS score of 8.1, exploitable over the network with no special privileges or complex attack setup required, though it does require user interaction to trigger. The primary impact is confidentiality compromise through memory disclosure, with secondary availability implications, though the assigned Chromium severity rating is notably low. The vulnerability shows minimal exploitation activity and community attention at this time, with no presence on the Known Exploited Vulnerabilities catalog and an EPSS probability score of 0.000860000 indicating very low real-world exploitation likelihood. This represents a moderate security concern that should be addressed through timely patching, but does not currently warrant emergency response measures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.