Vulnerabilities & Exploits

Critical Chrome WebML Bugs Signal New Sandbox Escape Risk

Chrome 147 fixes two critical memory corruption vulnerabilities in its WebML component, a newer browser feature for running machine learning models. The high $43,000 bounties and critical severity ratings indicate these bugs could allow attackers to escape the browser sandbox and execute code remotely, a risk that standard patching urgency often underestimates for emerging browser surfaces.

Google patched 60 vulnerabilities in Chrome 147, including a heap buffer overflow (CVE-2026-5858) and an integer overflow (CVE-2026-5859) in WebML. These flaws were reported by anonymous researchers and rewarded with top-tier bounties, signaling the elevated risk. The update also addresses other high-severity bugs across core browser components, but the WebML issues stand out due to their potential impact on endpoint security.

This release shifts the threat landscape by expanding the browser attack surface beyond traditional rendering and JavaScript engines to include WebML. Exploitation could lead to drive-by compromises on managed desktops, making immediate patching essential even without evidence of active exploitation.

1 source · Apr 10

CVE-2026-5858

NVD KEV

EPSS 0.6% (44th percentile). Microsoft patch: Release Notes.

CVE-2026-5859

NVD KEV

EPSS 0.4% (27th percentile). Microsoft patch: Release Notes.

Timeline

Sources

Part of the PlainSec briefing for 2026-04-11

Every edition of this story: Critical Chrome WebML Bugs Signal New Sandbox Escape Risk

More from today