Description
Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-04-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Information Disclosure
Action: Patch Update
AI Analysis

Impact

The vulnerability arises from insufficient validation of untrusted input in the WebML component of Google Chrome. A crafted HTML page can cause the browser to read data from its own process memory, allowing a remote attacker to retrieve potentially sensitive information. This does not result in code execution or a denial of service; the primary impact is the exposure of internal data that could be used for further attacks. The weakness is identified as improper input validation and unsafe memory handling, matching CWE‑20 and CWE‑1286.

Affected Systems

Google Chrome on Windows machines running any version prior to 147.0.7727.55 is affected. The issue was discovered in the Chrome binary that ships with Windows builds; no other operating systems or Chrome releases are reported to be impacted.

Risk and Exploitability

The CVSS score of 6.5 classifies the bug as Medium severity, and the EPSS score of less than 1 % indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited exploitation activity. Attackers would need to deliver a malicious HTML page to a user browsing in Chrome, typically through phishing or local files, to trigger the memory disclosure. Once triggered, the attacker can read the leaking data but cannot gain full control of the system. The overall risk to organizations is moderate, largely governed by how widely the specific vulnerable Chrome version is deployed and how often users access untrusted or user‑generated content.

Generated by OpenCVE AI on April 13, 2026 at 22:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Chrome security update to version 147.0.7727.55 or newer
  • Verify that all Windows users are running the patched version
  • If an immediate update is not possible, block or disable WebML in browser settings or via policy
  • Monitor for phishing or malicious HTML content that could exploit the vulnerability

Generated by OpenCVE AI on April 13, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6205-1 chromium security update
History

Mon, 13 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Mon, 13 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unvalidated WebML Input Enables Memory Information Disclosure in Chrome on Windows chromium-browser: Insufficient validation of untrusted input in WebML
Weaknesses CWE-1286
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Unvalidated WebML Input Enables Memory Information Disclosure in Chrome on Windows
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebML in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-13T18:18:39.369Z

Reserved: 2026-04-08T19:34:38.682Z

Link: CVE-2026-5885

cve-icon Vulnrichment

Updated: 2026-04-13T17:57:51.419Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-08T22:16:28.167

Modified: 2026-04-13T21:17:41.877

Link: CVE-2026-5885

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-07T00:00:00Z

Links: CVE-2026-5885 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:37:43Z

Weaknesses