CVE-2026-5909 is an integer overflow vulnerability in the Media component of Google Chrome versions prior to 147.0.7727.55 that could enable remote attackers to trigger heap corruption through specially crafted video files. The vulnerability requires user interaction to exploit but does not require authentication or special privileges. While Chromium assigned this a Low security severity rating, the CVSS score of 8.8 reflects high potential impact, including compromise of confidentiality, integrity, and availability of affected systems. This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score indicating it ranks lower than 99.75 percent of all CVEs in exploitation likelihood. Organizations should prioritize patching Chrome to version 147.0.7727.55 or later as part of routine security updates, though immediate emergency response is not warranted given the absence of active exploitation evidence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.