
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5273 is a use-after-free vulnerability in the CSS rendering engine of Google Chrome, allowing a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported by an anonymous researcher on March 18, 2026, and publicly disclosed on March 31, 2026, when Google released Chrome 146.0.7680.177/178. Affected versions include all Google Chrome releases prior to 146.0.7680.177 (Linux) / 146.0.7680.178 (Windows/Mac), as well as Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 6.3 (Medium) (Chrome Release Blog, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's CSS processing subsystem. When Chrome's renderer handles specially crafted CSS within an HTML page, it can reference memory that has already been freed, potentially allowing an attacker to control execution flow and run arbitrary code within the sandboxed renderer process. Exploitation requires user interaction — specifically, a victim visiting a malicious or attacker-controlled webpage — but requires no special privileges. The Chromium bug tracker entry is issue #493952652, though full technical details remain restricted pending broad user update rollout (Chrome Release Blog, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within Chrome's sandbox environment, affecting confidentiality, integrity, and availability at a low level each (per CVSS scoring). While Chrome's sandbox limits the immediate blast radius, code execution within the renderer process could serve as a stepping stone for sandbox escape chains, potentially enabling broader system compromise. All users running unpatched Chrome versions across Windows, Mac, and Linux are at risk, as are users of Chromium-based browsers such as Microsoft Edge (Chrome Release Blog, GitHub Advisory).
cmd.exe, powershell.exe, /bin/sh, curl, wget); Chrome renderer processes consuming abnormally high memory or crashing repeatedly.chrome_debug.log) showing heap corruption errors in CSS rendering components.Google has released patched versions: Chrome 146.0.7680.177 for Linux and 146.0.7680.178 for Windows and Mac. Users should update Chrome immediately via Settings > Help > About Google Chrome. Enterprise administrators should enforce the minimum version requirement across all managed Chrome installations using policy management tools. Microsoft Edge (Chromium-based) users should also apply available updates from Microsoft. No configuration-based workaround is available; patching is the only effective remediation (Chrome Release Blog, Microsoft MSRC).
The March 31, 2026 Chrome stable channel update received significant media attention primarily due to the co-disclosed CVE-2026-5281 (Use after free in Dawn), which Google confirmed was actively exploited in the wild. Coverage from outlets including The Hacker News, GBHackers, SecurityOnline, Forbes, and CyberSecurityNews focused on the broader update and the zero-day (CVE-2026-5281), with CVE-2026-5273 noted as part of the 21-fix security release. The Center for Internet Security (CIS) issued an advisory noting multiple vulnerabilities in the update could allow arbitrary code execution. The update was also flagged by Qualys and Tenable threat protection teams as part of their vulnerability tracking (Chrome Release Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."