CVE-2026-5914 is a type confusion vulnerability in the CSS handling engine of Google Chrome versions prior to 147.0.7727.55 that could allow heap corruption exploitation through malicious browser extensions. The vulnerability requires user interaction, specifically convincing a user to install a malicious extension, making it dependent on social engineering for successful exploitation. The vulnerability carries a CVSS score of 8.8 (HIGH) despite being assigned a low Chromium security severity rating, indicating potential for significant impact including confidentiality, integrity, and availability compromise. The attack vector is network-based with low complexity, though it requires user involvement and does not affect system scope. There is currently no evidence of active exploitation in the wild, with no existing public exploit code and minimal community attention based on its exclusion from the Known Exploited Vulnerabilities catalog and inactive status on vulnerability tracking lists. The EPSS score of 0.0002 suggests extremely low probability of exploitation in real-world conditions, indicating this remains a theoretical risk that has not translated into active threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.