Input validation error in Google Chromium - CVE-2026-5879

 

Input validation error in Google Chromium - CVE-2026-5879

Published: April 9, 2026


Vulnerability identifier: #VU125624
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-5879
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input in ANGLE in Google Chrome. A remote attacker can create a specially crafted web page, trick the victim into visiting it and gain access to sensitive information.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Debian Linux
Fedora
chromium
chromium (Debian package)

How to mitigate CVE-2026-5879

Install update from vendor's website.

Google Chromium - update to 147.0.7727.55
Microsoft Edge - update to 147.0.3912.60
Google Chrome - update to 147.0.7727.55
chromium - addressed in versions 147.0.7727.55-1.el9, 147.0.7727.55-1.el10_1, 147.0.7727.55-1.el10_2, 147.0.7727.55-1.el10_3, 147.0.7727.55-1.fc42, 147.0.7727.55-1.fc43, 147.0.7727.55-1.fc44, 147.0.7727.101-1.fc42
chromium (Debian package) - addressed in versions 147.0.7727.55-1~deb12u1, 147.0.7727.55-1~deb13u1

External References

Related Security Bulletins