Rapid7

vulnerability

FreeBSD: VID-4b727a1a-5034-42b4-b29b-2289389f4ba8 (CVE-2026-5868): chromium -- security fixes

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
Apr 10, 2026
Added
Apr 10, 2026
Modified
May 13, 2026

Description

Chrome Releases reports: This update includes multiple security fixes: Critical: CVE-2026-5858: Heap buffer overflow in WebML. CVE-2026-5859: Integer overflow in WebML. High: CVE-2026-5860: Use after free in WebRTC. CVE-2026-5861: Use after free in V8. CVE-2026-5862: Inappropriate implementation in V8. CVE-2026-5863: Inappropriate implementation in V8. CVE-2026-5864: Heap buffer overflow in WebAudio. CVE-2026-5865: Type Confusion in V8. CVE-2026-5866: Use after free in Media. CVE-2026-5867: Heap buffer overflow in WebML. CVE-2026-5868: Heap buffer overflow in ANGLE. CVE-2026-5869: Heap buffer overflow in WebML. CVE-2026-5870: Integer overflow in Skia. CVE-2026-5871: Type Confusion in V8. CVE-2026-5872: Use after free in Blink. CVE-2026-5873: Out of bounds read and write in V8. Medium: CVE-2026-5874: Use after free in PrivateAI. CVE-2026-5875: Policy bypass in Blink. CVE-2026-5876: Side-channel information leakage in Navigation. CVE-2026-5877: Use after free in Navigation. CVE-2026-5878: Incorrect security UI in Blink. CVE-2026-5879: Insufficient validation of untrusted input in ANGLE. CVE-2026-5880: Incorrect security UI in browser UI. CVE-2026-5881: Policy bypass in LocalNetworkAccess. CVE-2026-5882: Incorrect security UI in Fullscreen. CVE-2026-5883: Use after free in Media. CVE-2026-5884: Insufficient validation of untrusted input in Media. CVE-2026-5885: Insufficient validation of untrusted input in WebML. CVE-2026-5886: Out of bounds read in WebAudio. CVE-2026-5887: Insufficient validation of untrusted input in Downloads. CVE-2026-5888: Uninitialized Use in WebCodecs. CVE-2026-5889: Cryptographic Flaw in PDFium. CVE-2026-5890: Race in WebCodecs. CVE-2026-5891: Insufficient policy enforcement in browser UI. CVE-2026-5892: Insufficient policy enforcement in PWAs. CVE-2026-5893: Race in V8. Low: CVE-2026-5894: Inappropriate implementation in PDF. CVE-2026-5895: Incorrect security UI in Omnibox. CVE-2026-5896: Policy bypass in Audio. CVE-2026-5897: Incorrect security UI in Downloads. CVE-2026-5898: Incorrect security UI in Omnibox. CVE-2026-5899: Incorrect security UI in History Navigation. CVE-2026-5900: Policy bypass in Downloads. CVE-2026-5901: Policy bypass in DevTools. CVE-2026-5902: Race in Media. CVE-2026-5903: Policy bypass in IFrameSandbox. CVE-2026-5904: Use after free in V8. CVE-2026-5905: Incorrect security UI in Permissions. CVE-2026-5906: Incorrect security UI in Omnibox. CVE-2026-5907: Insufficient data validation in Media. CVE-2026-5908: Integer overflow in Media. CVE-2026-5909: Integer overflow in Media. CVE-2026-5910: Integer overflow in Media. CVE-2026-5911: Policy bypass in ServiceWorkers. CVE-2026-5912: Integer overflow in WebRTC. CVE-2026-5913: Out of bounds read in Blink. CVE-2026-5914: Type Confusion in CSS. CVE-2026-5915: Insufficient validation of untrusted input in WebML. CVE-2026-5918: Inappropriate implementation in Navigation. CVE-2026-5919: Insufficient validation of untrusted input in WebSockets.

Solutions

freebsd-upgrade-package-chromiumfreebsd-upgrade-package-ungoogled-chromium
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.