CVE-2026-5858
EPSS 0.6% (44th percentile). Microsoft patch: Release Notes.
Vulnerabilities · 158 days ago
Chrome 147 fixes two critical memory corruption vulnerabilities in its WebML component, a newer browser feature for running machine learning models. The high $43,000 bounties and critical severity ratings indicate these bugs could allow attackers to escape the browser sandbox and execute code remotely, a risk that standard patching urgency often underestimates for emerging browser surfaces.
Google patched 60 vulnerabilities in Chrome 147, including a heap buffer overflow (CVE-2026-5858) and an integer overflow (CVE-2026-5859) in WebML. These flaws were reported by anonymous researchers and rewarded with top-tier bounties, signaling the elevated risk. The update also addresses other high-severity bugs across core browser components, but the WebML issues stand out due to their potential impact on endpoint security.
This release shifts the threat landscape by expanding the browser attack surface beyond traditional rendering and JavaScript engines to include WebML. Exploitation could lead to drive-by compromises on managed desktops, making immediate patching essential even without evidence of active exploitation.
EPSS 0.6% (44th percentile). Microsoft patch: Release Notes.
EPSS 0.4% (27th percentile). Microsoft patch: Release Notes.
1 source covering this story
Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000
The critical vulnerabilities affect Chrome’s WebML component and they have been reported by anonymous researchers.
Part of the PlainSec briefing for 2026-04-11