Critical Chrome WebML Bugs Signal New Sandbox Escape Risk

Chrome 147 fixes two critical memory corruption vulnerabilities in its WebML component, a newer browser feature for running machine learning models. The high $43,000 bounties and critical severity ratings indicate these bugs could allow attackers to escape the browser sandbox and execute code remotely, a risk that standard patching urgency often underestimates for emerging browser surfaces. Google patched 60 vulnerabilities in Chrome 147, including a heap buffer overflow (CVE-2026-5858) and an integer overflow (CVE-2026-5859) in WebML. These flaws were reported by anonymous researchers and rewarded with top-tier bounties, signaling the elevated risk. The update also addresses other high-severity bugs across core browser components, but the WebML issues stand out due to their potential impact on endpoint security. This release shifts the threat landscape by expanding the browser attack surface beyond traditional rendering and JavaScript engines to include WebML. Exploitation could lead to drive-by compromises on managed desktops, making immediate patching essential even without evidence of active exploitation.

Part of the PlainSec briefing for 2026-04-11

Sources