CVE-2026-5908 is an integer overflow vulnerability in the Media component of Google Chrome prior to version 147.0.7727.55 that could allow remote attackers to trigger heap corruption through specially crafted video files. The vulnerability requires user interaction, as victims must open a malicious video file to be affected. While Chromium assigned it a low security severity rating, the CVSS score of 8.8 indicates high potential impact with compromised confidentiality, integrity, and availability. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild, with minimal community attention reflected in its low EPSS score and inactive status on public vulnerability tracking lists. Organizations should prioritize updating Chrome to version 147.0.7727.55 or later as part of routine patch management, though the low exploitation likelihood suggests this is not an immediate critical threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.