
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5272 is a heap-based buffer overflow vulnerability in the GPU component of Google Chrome that allows a remote attacker to execute arbitrary code via a crafted HTML page. It was reported by researcher "inspector-ambitious" on March 11, 2026, and publicly disclosed on March 31, 2026, when Google released Chrome 146.0.7680.177/178 to address it. The vulnerability affects all Google Chrome versions prior to 146.0.7680.177 (Linux) / 146.0.7680.178 (Windows/Mac), as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring in Chrome's GPU processing component. An attacker can trigger the overflow by delivering a specially crafted HTML page to a victim, causing Chrome's GPU subsystem to write beyond the bounds of a heap-allocated buffer. Exploitation requires user interaction — specifically, a victim visiting a malicious webpage — but has low attack complexity and requires no special privileges. The bug was tracked internally as Chromium issue 491732188, and bug details remain restricted pending broad user update (Chrome Releases, GitHub Advisory).
Successful exploitation could allow a remote attacker to execute arbitrary code with the privileges of the Chrome browser process, potentially leading to data theft, credential harvesting, malware installation, and full system compromise. All three security pillars are affected at a high level: confidentiality (access to sensitive browser data and system files), integrity (ability to modify data or install malicious software), and availability (potential crash or denial of service). The attack surface is broad, as any user running a vulnerable Chrome or Chromium-based browser version who visits a malicious page is at risk (GitHub Advisory).
chrome.exe --type=gpu-process spawning shells or scripting interpreters); abnormal GPU process crashes or restarts logged in system event logs.Google has released a patch in Chrome stable channel version 146.0.7680.177 for Linux and 146.0.7680.178 for Windows and Mac. Users should immediately update Chrome via Settings > Help > About Google Chrome and enable automatic updates to ensure timely patching. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a temporary measure, organizations can restrict user access to untrusted websites via web filtering policies and educate users about the risks of clicking unknown links (Chrome Releases, Microsoft MSRC).
The March 31, 2026 Chrome stable update attracted significant media attention primarily due to the co-patched CVE-2026-5281 (actively exploited zero-day in Dawn), with outlets such as GBHackers, The Hacker News, Cyber Security News, and Forbes covering the release under headlines referencing a Chrome zero-day under active exploitation. CVE-2026-5272 was covered as part of the broader 21-fix update bundle. The CIS issued an advisory noting multiple vulnerabilities in Google Chrome could allow arbitrary code execution (CIS Advisory). Downstream Linux distributions including Fedora, openSUSE, Debian, and FreeBSD also issued Chromium security updates addressing this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."