CVE-2026-5915 is an insufficient input validation vulnerability in WebML within Google Chrome versions prior to 147.0.7727.55 that permits remote attackers to execute out-of-bounds memory writes through maliciously crafted HTML pages. The vulnerability affects Google Chrome and potentially other Chromium-based browsers that incorporate the vulnerable WebML component. The vulnerability carries a CVSS 3.1 score of 8.1 (HIGH) with a network-based attack vector requiring no privileges but user interaction through clicking a crafted link. While the Chromium security team initially rated this as LOW severity, the CVSS scoring reflects significant impact potential, with high integrity and availability compromises possible. The attack requires minimal complexity and no special privileges beyond user interaction. There is currently no evidence of active exploitation in the wild, as the vulnerability is not present on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. The EPSS score of 0.001 indicates this vulnerability is lower priority compared to the broader CVE landscape, suggesting minimal public exploit code availability or proof-of-concept demonstrations at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.