CVE-2026-5284
vulnerability analysis and mitigation

Overview

CVE-2026-5284 is a use-after-free vulnerability in the Dawn graphics library within Google Chrome, allowing a remote attacker who has already compromised the renderer process to execute arbitrary code via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.177/178 and Microsoft Edge (Chromium-based). The vulnerability was reported on March 12, 2026, by researcher 86ac1f1587b71893ed2ad792cd7dde32 (Chromium issue #492139412), and patches were released on March 31, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Chrome Release Blog, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and resides in Dawn, Chrome's cross-platform graphics abstraction layer used for WebGPU. A use-after-free condition occurs when memory associated with a Dawn object is freed but a dangling pointer to that memory is subsequently accessed, enabling an attacker to control freed memory and redirect execution flow. Exploitation requires the attacker to have already compromised the Chrome renderer process — meaning this vulnerability is typically used as a second-stage exploit in a renderer-plus-sandbox-escape chain, triggered via a specially crafted HTML page. The attack vector is network-based, requires user interaction (visiting a malicious page), and has high attack complexity (Chrome Release Blog, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker who has compromised the Chrome renderer process to execute arbitrary code within the context of the browser process, potentially achieving full system compromise. The vulnerability has high confidentiality, integrity, and availability impact, meaning an attacker could access sensitive data, modify system state, or disrupt service. Because exploitation requires a pre-compromised renderer, this vulnerability is most dangerous when chained with a separate renderer exploit (such as the actively exploited CVE-2026-5281, also patched in the same update) (Chrome Release Blog, GitHub Advisory).

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 146.0.7680.177 (Linux) and 146.0.7680.178 (Windows/Mac). Users and organizations should update Google Chrome immediately to version 146.0.7680.178 or later. Microsoft Edge (Chromium-based) users should also apply the corresponding Microsoft security update. Organizations should enforce automated browser update policies to ensure all endpoints are running patched versions, and consider implementing content security policies and sandboxing restrictions to reduce the risk of renderer compromise (Chrome Release Blog, Microsoft MSRC).

Community reactions

The March 31, 2026 Chrome update attracted significant media attention primarily due to the confirmed in-the-wild exploitation of the related CVE-2026-5281 (also a Dawn use-after-free), with outlets including The Hacker News, GBHackers, HelpNet Security, Forbes, and CyberSecurityNews covering the emergency update. CVE-2026-5284 was reported alongside CVE-2026-5281 in the same update and received coverage as part of the broader Chrome zero-day story. The CIS issued an advisory noting multiple vulnerabilities in Google Chrome could allow arbitrary code execution (CIS Advisory). Palo Alto Networks also issued a Chromium monthly vulnerability update advisory (PAN-SA-2026-0004) covering this CVE (Palo Alto Advisory).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management