CVE-2026-5902
A race condition in Google Chrome’s media handling on Android allows a remote attacker who has already compromised the renderer process to corrupt media stream metadata via a crafted HTML page. This flaw can compromise the confidentiality, integrity, and availability of media data. The vulnerability is rated critical with a CVSS score of 9.8.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Google Chrome on Android versions prior to 147.0.7727.55 (and other listed CPEs such as Apple macOS, Linux kernel, Microsoft Windows, though the specific flaw is reported for Chrome on Android).
Real-world impact
An attacker who can execute code in the renderer process could modify or corrupt the metadata of media streams, potentially causing playback errors, data leakage, or denial of service for users viewing media content.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited remotely without authentication or user interaction, and it can completely compromise confidentiality, integrity, and availability of media data. The high impact on all three core security objectives drives the critical rating.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Apr 8, 2026 · Apr 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/04/stable-channel-upda…release notesvendor advisory
- issues.chromium.org/issues/483109205issue trackingpermissions required