Insufficient Input Validation in WebSockets in Google Chrome by Google
CVE-2026-5919

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-5919?

A vulnerability in Google Chrome prior to version 147.0.7727.55 allows a remote attacker to exploit insufficient validation of untrusted input in WebSockets. By leveraging this flaw, the attacker can bypass the same origin policy through a specially crafted HTML page, potentially leading to unauthorized access and manipulation of sensitive data.

Affected Version(s)

Chrome 147.0.7727.55

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.