CVE-2026-5858
EPSS 0.6% (45º percentile). Patch Microsoft: Release Notes.
Vulnerabilità · 175 giorni fa
Chrome 147 corregge due vulnerabilità critiche di corruzione della memoria nel suo componente WebML, una funzionalità più recente del browser per l’esecuzione di modelli di machine learning. I premi elevati da 43.000$ e le valutazioni di gravità critica indicano che questi bug potrebbero consentire agli attaccanti di evadere la sandbox del browser ed eseguire codice da remoto, un rischio che l’urgenza standard di patching spesso sottovaluta per superfici emergenti del browser.
EPSS 0.6% (45º percentile). Patch Microsoft: Release Notes.
EPSS 0.3% (25º percentile). Patch Microsoft: Release Notes.
1 fonte che coprono questa storia
Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000
The critical vulnerabilities affect Chrome’s WebML component and they have been reported by anonymous researchers.
Part of the PlainSec briefing for 2026-04-11