
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5278 is a use-after-free vulnerability in the Web MIDI component of Google Chrome on Android, allowing a remote attacker to execute arbitrary code via a crafted HTML page. The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 6, 2026, and publicly disclosed on March 31, 2026, as part of a broader Chrome stable channel update. It affects Google Chrome for Android versions prior to 146.0.7680.178. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The root cause is a use-after-free condition (CWE-416) in Chrome's Web MIDI implementation on Android, where memory is accessed after it has been freed, potentially allowing an attacker to control freed memory and redirect execution flow. Exploitation requires a victim to visit or be redirected to a malicious HTML page, at which point the crafted page triggers the Web MIDI subsystem to access deallocated memory. The attack vector is network-based with low complexity, requiring no privileges but necessitating user interaction (e.g., visiting a malicious URL). The Chromium issue tracker entry is tracked under issue ID 490254128, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).
Successful exploitation can result in complete compromise of the affected Android device, including arbitrary code execution in the context of the Chrome browser process. This may lead to data theft, malware installation, credential harvesting, and potentially full device control depending on the attacker's payload and any additional privilege escalation steps. Confidentiality, integrity, and availability are all rated as High impact (GitHub Advisory, Chrome Releases).
Google has released a fix in Chrome version 146.0.7680.178 for Android (and 146.0.7680.177/178 for Windows/Mac/Linux). Users should immediately update Google Chrome on all Android devices to version 146.0.7680.178 or later via the Google Play Store. As a temporary workaround while patching, organizations can restrict access to untrusted or unknown websites and consider disabling Web MIDI API access via enterprise policy if supported. Monitoring for suspicious browser activity on Android devices is also recommended (Chrome Releases, GitHub Advisory).
The March 31, 2026 Chrome update received significant media attention primarily due to the co-disclosed CVE-2026-5281 (use-after-free in Dawn), which Google confirmed was being actively exploited in the wild. Coverage from GBHackers, CyberSecurityNews, The Hacker News, Forbes, and CyberPress focused on the broader zero-day threat in the update batch, with CVE-2026-5278 noted as one of 21 security fixes. The CIS issued an advisory noting multiple vulnerabilities in Google Chrome could allow arbitrary code execution. Community and researcher sentiment emphasized urgency to update Chrome, particularly given the active exploitation of a related vulnerability in the same release (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."