
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5282 is an out-of-bounds read vulnerability in the WebCodecs component of Google Chrome, allowing a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. It affects all versions of Google Chrome prior to 146.0.7680.177 (Linux) / 146.0.7680.178 (Windows/Mac). The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 11, 2026, and publicly disclosed on March 31, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.1 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's WebCodecs API, which provides low-level access to media encoding and decoding functionality. An attacker can exploit this by crafting a malicious HTML page that triggers improper buffer boundary checks within the WebCodecs component, causing the browser to read memory beyond the intended buffer. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but no authentication or elevated privileges are needed. The Chromium issue tracker entry is #491655161 (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to read memory outside the intended buffer boundaries within the Chrome browser process, potentially exposing sensitive in-memory data such as session tokens, authentication credentials, or other confidential information. The CVSS scoring reflects high confidentiality and availability impact with no integrity impact, meaning the vulnerability can lead to information disclosure and potential browser instability or crash. While the vulnerability is confined to the browser sandbox, leaked memory contents could facilitate further attacks or credential theft (GitHub Advisory, Chrome Releases).
Google has released a patch in Chrome stable channel version 146.0.7680.177 for Linux and 146.0.7680.178 for Windows and Mac. Users should immediately update Chrome to the patched version via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or by enabling automatic updates. As an interim measure, organizations should consider restricting or monitoring WebCodecs API usage via enterprise policy, and users should avoid visiting untrusted websites until patching is complete. Downstream distributions (Debian, openSUSE, Fedora, FreeBSD) have also released updated Chromium packages (Chrome Releases).
The March 31, 2026 Chrome update received significant media attention primarily due to the co-patched CVE-2026-5281 (actively exploited zero-day), with outlets including Forbes, The Hacker News, GBHackers, and CyberPress covering the release under headlines about a Chrome zero-day under active exploitation. CIS issued an advisory noting multiple vulnerabilities in the update could allow arbitrary code execution. CVE-2026-5282 itself was noted as part of the broader 21-fix security update but did not receive individual spotlight coverage separate from the zero-day narrative (Chrome Releases, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."