Google has released version Chrome 147 to the stable channel for Windows, macOS, and Linux , closing a large set of vulnerabilities that could be exploited by cybercriminals. Among them are two critical security holes that – under certain conditions – allow remote malicious code execution of , putting users' systems at immediate risk.

These two bugs, CVE-2026-5858 and CVE-2026-5859, are located in the WebML subsystem, a relatively new part of the browser designed to accelerate machine learning operations directly within the browser environment. Their severity is reflected in the high bug bounty rewards offered for their discovery.
Critical gaps in WebML and their implications
These vulnerabilities are related to memory management errors – one of the most enduring and dangerous problems in software.
CVE-2026-5858 is a heap buffer overflow, while CVE-2026-5859 is an integer overflow. Both can be triggered via maliciously crafted HTML pages.
See also: Anthropic AI Mythos Preview: Helps Apple Find Vulnerabilities
In practice, this means that an attacker could trick the browser into writing data beyond its allowed memory limits. Such a breach opens the way to complete control of the browser process, allowing arbitrary code to be executed without user intervention.
The fact that the bugs are being found in WebML raises broader questions about the security of emerging technologies within browsers. As more and more artificial intelligence functions are moved client-side, the attack surface also increases.

A plethora of high-severity vulnerabilities
In addition to the two critical flaws, the update also fixes 14 vulnerabilities affecting key components such as WebRTC, the V8 JavaScript engine, and the graphics system:
- CVE-2026-5860 – Use-after-free in WebRTC ($11,000 bounty)
- CVE-2026-5861 – Use-after-free in V8 JavaScript engine ($3,000 bounty)
- CVE-2026-5862 & CVE-2026-5863 – Inappropriate implementation in V8 (reported internally by Google)
- CVE-2026-5864 – Heap buffer overflow in WebAudio, reported by Syn4pse
- CVE-2026-5865 – Type Confusion in V8, reported by Project WhatForLunch
- CVE-2026-5866 – Use-after-free in Media
- CVE-2026-5867 & CVE-2026-5869 – Heap buffer overflows in WebML
- CVE-2026-5868 – Heap buffer overflow in ANGLE graphics layer
- CVE-2026-5870 & CVE-2026-5871 – Integer overflow in Skia and Type Confusion in V8
- CVE-2026-5872 & CVE-2026-5873 – Use-after-free in Blink and out-of-bounds read/write in V8
Of particular concern are the so-called “ use-after-free ” bugs and “ type confusion ” errors in V8. These categories of vulnerabilities are considered extremely dangerous, as they can be exploited as a “bridge” to bypass the browser sandbox – one of the main layers of defense against attacks.
See also: Ninja Forms – File Upload: Vulnerability puts thousands of WordPress sites at risk
Combined with renderer exploits, such vulnerabilities can lead to a complete system compromise, turning a simple visit to a malicious website into a serious security incident.
Smaller flaws with great significance
The new version also addresses dozens of medium and low severity vulnerabilities, which should not be underestimated. Many of these flaws are related to security policy bypasses, user interface issues, and incomplete data validation.
While individually they may seem less dangerous, in practice they can be used in combination with other exploits, forming complex attack chains. For example, an attacker could spoof trusted browser UI elements or bypass content protection mechanisms, enhancing the effectiveness of a larger attack.

The role of fuzzing in threat detection
Google's advanced fuzzing infrastructure proved crucial in identifying vulnerabilities . Tools such as AddressSanitizer, MemorySanitizer, and libFuzzer allow for automatic detection of errors through testing with random data, before they are exploited by malicious actors.
This approach is now a key pillar of modern software security, especially for large-scale applications such as browsers, which are a daily target of attacks.
See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment
Why you should update to Chrome 147 immediately
The vulnerabilities affect older versions of Chrome prior to 147.0.7727.55 for Linux and 147.0.7727.55/56 for Windows and Mac. Users can easily upgrade via the browser's settings.
In an era where attacks are becoming increasingly sophisticated, regular software updates remain one of the simplest yet most effective lines of defense. This upgrade is not just another update — it is a critical shield of protection against real and imminent threats.
