CVE-2026-5282
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-5282 is an out-of-bounds read vulnerability in the WebCodecs component of Google Chrome, allowing a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. It affects all versions of Google Chrome prior to 146.0.7680.177 (Linux) / 146.0.7680.178 (Windows/Mac). The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 11, 2026, and publicly disclosed on March 31, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.1 (High) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's WebCodecs API, which provides low-level access to media encoding and decoding functionality. An attacker can exploit this by crafting a malicious HTML page that triggers improper buffer boundary checks within the WebCodecs component, causing the browser to read memory beyond the intended buffer. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but no authentication or elevated privileges are needed. The Chromium issue tracker entry is #491655161 (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to read memory outside the intended buffer boundaries within the Chrome browser process, potentially exposing sensitive in-memory data such as session tokens, authentication credentials, or other confidential information. The CVSS scoring reflects high confidentiality and availability impact with no integrity impact, meaning the vulnerability can lead to information disclosure and potential browser instability or crash. While the vulnerability is confined to the browser sandbox, leaked memory contents could facilitate further attacks or credential theft (GitHub Advisory, Chrome Releases).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 146.0.7680.177/178 on Windows, Mac, or Linux using passive fingerprinting or social engineering.
  2. Craft malicious HTML page: Develop a web page that invokes the WebCodecs API with specially crafted media data designed to trigger an out-of-bounds read condition in the vulnerable component (Chromium issue #491655161).
  3. Deliver the payload: Host the malicious HTML page on an attacker-controlled server and lure the victim to visit it via phishing, malvertising, or a compromised website — user interaction (page visit) is required.
  4. Trigger out-of-bounds read: When the victim's Chrome browser processes the crafted WebCodecs input, the browser reads memory beyond the intended buffer boundary.
  5. Extract sensitive data: The out-of-bounds read may expose in-memory data (e.g., session tokens, credentials) that can be exfiltrated back to the attacker via JavaScript or network requests, depending on the specific memory layout at the time of exploitation (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP/HTTPS connections from the browser process to unknown or suspicious external IPs shortly after visiting an unfamiliar website; unusual data exfiltration patterns from the browser.
  • Logs: Browser crash reports or renderer process crashes associated with WebCodecs API usage; Chrome crash dumps referencing out-of-bounds memory access in WebCodecs-related stack frames.
  • Process: Chrome renderer processes spawning unusual child processes or exhibiting abnormal memory access patterns; unexpected JavaScript execution involving WebCodecs API calls on visited pages.
  • File System: Unexpected files written to the Chrome user profile directory or temporary directories following visits to suspicious pages.

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 146.0.7680.177 for Linux and 146.0.7680.178 for Windows and Mac. Users should immediately update Chrome to the patched version via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or by enabling automatic updates. As an interim measure, organizations should consider restricting or monitoring WebCodecs API usage via enterprise policy, and users should avoid visiting untrusted websites until patching is complete. Downstream distributions (Debian, openSUSE, Fedora, FreeBSD) have also released updated Chromium packages (Chrome Releases).

Community reactions

The March 31, 2026 Chrome update received significant media attention primarily due to the co-patched CVE-2026-5281 (actively exploited zero-day), with outlets including Forbes, The Hacker News, GBHackers, and CyberPress covering the release under headlines about a Chrome zero-day under active exploitation. CIS issued an advisory noting multiple vulnerabilities in the update could allow arbitrary code execution. CVE-2026-5282 itself was noted as part of the broader 21-fix security update but did not receive individual spotlight coverage separate from the zero-day narrative (Chrome Releases, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15767HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui-debuginfo
NoYesJul 14, 2026
CVE-2026-15769HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium-common
NoYesJul 14, 2026
CVE-2026-15770MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromedriver
NoYesJul 14, 2026
CVE-2026-15768MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesJul 14, 2026
CVE-2026-15766MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui-debuginfo
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management