
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5285 is a use-after-free vulnerability in the WebGL component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.177/178 and Microsoft Edge (Chromium-based). The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 13, 2026, and patched on March 31, 2026, with public disclosure on April 1, 2026. It carries a CVSS v3.1 base score of 8.8 (High) per NVD (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's WebGL subsystem — the browser's implementation of the OpenGL ES graphics API for rendering 3D content in web pages. A use-after-free condition arises when memory associated with a WebGL object is freed but a dangling reference to that memory is subsequently accessed, allowing an attacker to control or corrupt heap memory. Exploitation requires a victim to visit a specially crafted HTML page, triggering the memory corruption within the renderer process. The bug was tracked internally as Chromium issue #492228019 (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, potentially enabling further sandbox escape attempts, data theft from the browser context, or use as a stepping stone for broader system compromise. The vulnerability affects confidentiality, integrity, and availability at a high level within the sandbox scope. Because exploitation is limited to the sandbox, a full system compromise would typically require chaining with an additional sandbox escape vulnerability (GitHub Advisory, Chrome Releases).
cmd.exe, powershell.exe, bash, curl) that are not typical browser behavior; Chrome renderer processes consuming abnormally high memory.Users and administrators should immediately update Google Chrome to version 146.0.7680.178 (Windows/Mac) or 146.0.7680.177 (Linux) or later, which contains the fix for this vulnerability. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Enabling Chrome's automatic update mechanism ensures timely patching. As an interim measure, users should avoid visiting untrusted or suspicious websites, since user interaction (visiting a malicious page) is required to trigger the vulnerability (Chrome Releases, Microsoft MSRC).
The March 31, 2026 Chrome stable update received significant media attention primarily due to the co-patched CVE-2026-5281 (Use after free in Dawn), which Google confirmed was actively exploited in the wild. Security outlets including GBHackers, CyberSecurityNews, CyberPress, The Hacker News, and Forbes covered the release, often framing it as a zero-day emergency update. The CIS issued an advisory noting multiple vulnerabilities in the update could allow arbitrary code execution. CVE-2026-5285 itself was noted as part of the broader 21-fix release but did not receive individual spotlight coverage separate from the zero-day narrative around CVE-2026-5281 (Chrome Releases, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."