Description
Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-04-08
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An integer overflow in the Skia graphics engine of Google Chrome allows a remote attacker to execute arbitrary code while the browser process remains sandboxed. The flaw, classified as CWE‑472, is triggered by a specially crafted HTML page served to a user’s browser. Because the malicious payload runs inside the sandbox, an attacker could gain control of the browser process, potentially allowing data exfiltration or manipulation of the user session.

Affected Systems

All users running a Chrome stable channel version earlier than 147.0.7727.55 are affected. The vulnerability is present in every build before that revision, regardless of operating system. Updating to any Chrome release equal to or newer than 147.0.7727.55 removes the flaw.

Risk and Exploitability

Chromium has labeled the issue as high severity. A remote attacker can trigger the overflow by loading a malicious web page, and the vulnerability has not been listed in CISA’s Known Exploited Vulnerabilities catalog. EPSS information is not available, but the combination of a high severity rating and the ability to launch the attack over the Internet indicates a significant risk for unpatched users.

Generated by OpenCVE AI on April 9, 2026 at 00:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 147.0.7727.55 or newer, which contains a patch for the Skia overflow.
  • Verify that automatic updates are enabled so that future security patches are applied automatically.

Generated by OpenCVE AI on April 9, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6205-1 chromium security update
History

Fri, 10 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Skia Enables Remote Code Execution in Chrome chromium-browser: Integer overflow in Skia
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Skia Enables Remote Code Execution in Chrome
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Integer overflow in Skia in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-10T03:55:50.570Z

Reserved: 2026-04-08T19:34:34.701Z

Link: CVE-2026-5870

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:26.580

Modified: 2026-04-08T22:16:26.580

Link: CVE-2026-5870

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-07T00:00:00Z

Links: CVE-2026-5870 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:56Z

Weaknesses