CVE-2026-5890
published 2026-04-08CVE-2026-5890: Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a…
PriorityP426medium5.3CVSS 3.1
AVNACHPRNUIRSUCHINAN
EPSS
0.18%
7.9th percentile
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 147.0.7727.55-1 (sid) | chromium 147.0.7727.55-1 (sid) |
| chrome | < 147.0.7727.55 | 147.0.7727.55 | |
| chrome | >= 147.0.7727.55 < 147.0.7727.55 | 147.0.7727.55 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 146.0.7680.178 WebCodecs race condition (ID 487259 / WID-SEC-2026-1030)
vuldb·2026-04-11
CVE-2026-5890 [LOW] Google Chrome up to 146.0.7680.178 WebCodecs race condition (ID 487259 / WID-SEC-2026-1030)
A vulnerability was found in Google Chrome. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component WebCodecs. Performing a manipulation results in race condition.
This vulnerability was named CVE-2026-5890. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
GHSA
GHSA-2fw9-cxch-qx5h: Race in WebCodecs in Google Chrome prior to 147
ghsa_unreviewed·2026-04-09
CVE-2026-5890 CWE-362 GHSA-2fw9-cxch-qx5h: Race in WebCodecs in Google Chrome prior to 147
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2026-5890: Race in WebCodecs in Google Chrome prior to 147
osv·2026-04-08
CVE-2026-5890 CVE-2026-5890: Race in WebCodecs in Google Chrome prior to 147
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5890
vendor_chrome·2026-04-22
CVE-2026-5890 Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5890
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-5890
Chrome
Stable Channel Update for Desktop: CVE-2026-5888
vendor_chrome·2026-04-07·CVSS 6.5
CVE-2026-5888 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-5888
Stable Channel Update for Desktop
CVE-2026-5888: Uninitialized Use in WebCodecs. Reported by Identified by the Octane Security Team: Giovanni Vignone, Paolo Gentry, Robert van Eijk on 2026-02-22 [TBD][ 486906037 ] Medium CVE-2026-5889: Cryptographic Flaw in PDFium
Reported by mlafon on 2026-02-23 [TBD][ 487259772 ] Medium CVE-2026-5890: Race in WebCodecs
Severity: medium
Red Hat
chromium-browser: Race in WebCodecs
vendor_redhat·2026-04-07·CVSS 6.5
CVE-2026-5890 [MEDIUM] CWE-368 chromium-browser: Race in WebCodecs
chromium-browser: Race in WebCodecs
A race flaw was found in the WebCodecs component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=487259772
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Debian
CVE-2026-5890: chromium - Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attac...
vendor_debian·2026
CVE-2026-5890 CVE-2026-5890: chromium - Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attac...
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5890 chromium-browser: Race in WebCodecs
bugzilla·2026-04-08
CVE-2026-5890 [MEDIUM] CVE-2026-5890 chromium-browser: Race in WebCodecs
CVE-2026-5890 chromium-browser: Race in WebCodecs
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Sans Isc
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
blogs_sans_isc·2026-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026.
Published: 2026-04-14. Last Updated: 2026-04-14 17:46:09 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month's Microsoft Patch Tuesday looks like a record one, but let's look at it a bit closer to understand what is happening
The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.
Noteworthy Vulnerabilities:
CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love thes
Wiz
CVE-2026-5890 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5890 [HIGH] CVE-2026-5890 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5890 :
Google Chrome vulnerability analysis and mitigation
Race in WebCodecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Source : NVD
Published April 8, 2026
CNA Score N/A
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
chromium
cpe:2.3:a:google:chrome
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: Apr 09, 2026
Echo No Fix Added at: Apr 09, 2026
Linux Has Fix Added at: Apr 09, 2026
Windows Has Fix Added
2026-04-08
Published