CVE-2026-5893
published 2026-04-08CVE-2026-5893: Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security…
PriorityP335medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
EPSS
0.15%
4.6th percentile
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 147.0.7727.55-1 (sid) | chromium 147.0.7727.55-1 (sid) |
| chrome | < 147.0.7727.55 | 147.0.7727.55 | |
| chrome | >= 147.0.7727.55 < 147.0.7727.55 | 147.0.7727.55 | |
| chrome_chrome | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
vendor_paloalto·2026-05-13·CVSS 8.8
CVE-2026-4439 [HIGH] PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_22.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html CVE Summary CVE-2026-4439 Out of bounds memory access in WebGL CVE-2026-4440 Out of bounds read and write in WebGL CVE-2026-4441 Use after free in Base CVE-2026-4442 Heap buffer overflow in
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5893
vendor_chrome·2026-04-22·CVSS 6.8
CVE-2026-5893 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5893
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-5893
Red Hat
chromium-browser: Race in V8
vendor_redhat·2026-04-07·CVSS 6.8
CVE-2026-5893 [MEDIUM] CWE-366 chromium-browser: Race in V8
chromium-browser: Race in V8
A race flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=487768771
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-5891
vendor_chrome·2026-04-07·CVSS 4.3
CVE-2026-5891 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-5891
Stable Channel Update for Desktop
CVE-2026-5891: Insufficient policy enforcement in browser UI. Reported by Tianyi Hu on 2026-02-25 [TBD][ 487568011 ] Medium CVE-2026-5892: Insufficient policy enforcement in PWAs
Reported by Tianyi Hu on 2026-02-25 [TBD][ 487768771 ] Medium CVE-2026-5893: Race in V8
Severity: medium
Debian
CVE-2026-5893: chromium - Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to ...
vendor_debian·2026·CVSS 6.8
CVE-2026-5893 [MEDIUM] CVE-2026-5893: chromium - Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to ...
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
VulDB
Google Chrome up to 146.0.7680.178 V8 race condition (ID 487768 / WID-SEC-2026-1030)
vuldb·2026-04-11·CVSS 6.8
CVE-2026-5893 [MEDIUM] Google Chrome up to 146.0.7680.178 V8 race condition (ID 487768 / WID-SEC-2026-1030)
A vulnerability was found in Google Chrome and classified as problematic. This vulnerability affects unknown code of the component V8. Executing a manipulation can lead to race condition.
This vulnerability appears as CVE-2026-5893. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
GHSA-44vf-4x73-jv4x: Race in V8 in Google Chrome prior to 147
ghsa_unreviewed·2026-04-09
CVE-2026-5893 CWE-362 GHSA-44vf-4x73-jv4x: Race in V8 in Google Chrome prior to 147
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2026-5893: Race in V8 in Google Chrome prior to 147
osv·2026-04-08·CVSS 6.8
CVE-2026-5893 [MEDIUM] CVE-2026-5893: Race in V8 in Google Chrome prior to 147
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-43460 kernel: spi: rockchip-sfc: Fix double-free in remove() callback
bugzilla·2026-05-08
CVE-2026-43460 CVE-2026-43460 kernel: spi: rockchip-sfc: Fix double-free in remove() callback
CVE-2026-43460 kernel: spi: rockchip-sfc: Fix double-free in remove() callback
In the Linux kernel, the following vulnerability has been resolved:
spi: rockchip-sfc: Fix double-free in remove() callback
The driver uses devm_spi_register_controller() for registration, which
automatically unregisters the controller via devm cleanup when the
device is removed. The manual call to spi_unregister_controller() in
the remove() callback can lead to a double-free.
And to make sure controller is unregistered before DMA buffer is
unmapped, switch to use spi_register_controller() in probe().
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2026050801-CVE-2026-43460-5893@gregkh/T
Bugzilla
CVE-2026-5893 chromium-browser: Race in V8
bugzilla·2026-04-08·CVSS 6.8
CVE-2026-5893 [MEDIUM] CVE-2026-5893 chromium-browser: Race in V8
CVE-2026-5893 chromium-browser: Race in V8
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Sans Isc
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
blogs_sans_isc·2026-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026.
Published: 2026-04-14. Last Updated: 2026-04-14 17:46:09 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month's Microsoft Patch Tuesday looks like a record one, but let's look at it a bit closer to understand what is happening
The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.
Noteworthy Vulnerabilities:
CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love thes
Wiz
CVE-2026-5893 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5893 [HIGH] CVE-2026-5893 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5893 :
Google Chrome vulnerability analysis and mitigation
Race in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Source : NVD
Published April 8, 2026
CNA Score N/A
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:google:chrome
chromium
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: Apr 09, 2026
Echo No Fix Added at: Apr 09, 2026
Linux Has Fix Added at: Apr 09, 2026
Windows Has Fix Added at: Apr 09, 2026
## Get a CVE
2026-04-08
Published