CVE-2026-5278
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-5278 is a use-after-free vulnerability in the Web MIDI component of Google Chrome on Android, allowing a remote attacker to execute arbitrary code via a crafted HTML page. The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 6, 2026, and publicly disclosed on March 31, 2026, as part of a broader Chrome stable channel update. It affects Google Chrome for Android versions prior to 146.0.7680.178. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).

Technical details

The root cause is a use-after-free condition (CWE-416) in Chrome's Web MIDI implementation on Android, where memory is accessed after it has been freed, potentially allowing an attacker to control freed memory and redirect execution flow. Exploitation requires a victim to visit or be redirected to a malicious HTML page, at which point the crafted page triggers the Web MIDI subsystem to access deallocated memory. The attack vector is network-based with low complexity, requiring no privileges but necessitating user interaction (e.g., visiting a malicious URL). The Chromium issue tracker entry is tracked under issue ID 490254128, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation can result in complete compromise of the affected Android device, including arbitrary code execution in the context of the Chrome browser process. This may lead to data theft, malware installation, credential harvesting, and potentially full device control depending on the attacker's payload and any additional privilege escalation steps. Confidentiality, integrity, and availability are all rated as High impact (GitHub Advisory, Chrome Releases).

Exploitation steps

  1. Reconnaissance: Identify Android users running Google Chrome versions prior to 146.0.7680.178 as potential targets, using social engineering or targeting high-value individuals.
  2. Craft malicious HTML page: Develop a web page that triggers the Web MIDI API in a way that causes a use-after-free condition in Chrome's Web MIDI subsystem on Android — for example, by manipulating MIDI port objects to be freed and then accessed through stale references.
  3. Deliver the payload: Lure the target into visiting the malicious page via phishing email, malicious advertisement, or compromised website. User interaction (clicking a link or visiting the page) is required.
  4. Trigger the vulnerability: When the victim's Chrome browser processes the crafted HTML/JavaScript, the Web MIDI component accesses freed memory, enabling the attacker to potentially control execution flow.
  5. Achieve code execution: With successful memory manipulation, execute a shellcode payload or ROP chain to achieve arbitrary code execution within the Chrome renderer process on the Android device, potentially enabling data exfiltration or further exploitation (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from an Android device's Chrome process to unknown or suspicious IP addresses following a web browsing session; HTTP/HTTPS requests to newly registered or low-reputation domains that serve pages invoking the Web MIDI API.
  • Logs: Chrome crash reports or renderer process crashes on Android devices associated with Web MIDI activity; Android system logs showing abnormal process spawning from the Chrome browser process.
  • Process: Unusual child processes or shell activity originating from the Chrome renderer on Android; unexpected background services or applications installed following a browsing session.
  • File System: Unexpected files written to Chrome's application data directory or to world-readable locations on the Android device following a browsing session.

Mitigation and workarounds

Google has released a fix in Chrome version 146.0.7680.178 for Android (and 146.0.7680.177/178 for Windows/Mac/Linux). Users should immediately update Google Chrome on all Android devices to version 146.0.7680.178 or later via the Google Play Store. As a temporary workaround while patching, organizations can restrict access to untrusted or unknown websites and consider disabling Web MIDI API access via enterprise policy if supported. Monitoring for suspicious browser activity on Android devices is also recommended (Chrome Releases, GitHub Advisory).

Community reactions

The March 31, 2026 Chrome update received significant media attention primarily due to the co-disclosed CVE-2026-5281 (use-after-free in Dawn), which Google confirmed was being actively exploited in the wild. Coverage from GBHackers, CyberSecurityNews, The Hacker News, Forbes, and CyberPress focused on the broader zero-day threat in the update batch, with CVE-2026-5278 noted as one of 21 security fixes. The CIS issued an advisory noting multiple vulnerabilities in Google Chrome could allow arbitrary code execution. Community and researcher sentiment emphasized urgency to update Chrome, particularly given the active exploitation of a related vulnerability in the same release (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15767HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui-debuginfo
NoYesJul 14, 2026
CVE-2026-15769HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium-common
NoYesJul 14, 2026
CVE-2026-15770MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromedriver
NoYesJul 14, 2026
CVE-2026-15768MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesJul 14, 2026
CVE-2026-15766MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui-debuginfo
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management