
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5287 is a use-after-free vulnerability in the PDF handler of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted PDF file. It was reported by researcher Syn4pse on March 21, 2026, and publicly disclosed on March 31, 2026, when Google released Chrome 146.0.7680.177/178 to address it. The vulnerability affects all Google Chrome versions prior to 146.0.7680.178, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, GitHub Advisory, Feedly).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's PDF rendering component. When Chrome processes a specially crafted PDF file, a memory management flaw allows the browser to reference memory that has already been freed; an attacker can manipulate this freed memory region to redirect code execution. Exploitation requires user interaction — specifically, a victim must open or view a malicious PDF file in the browser. The Chromium issue tracker entry is #494644471, though full technical details remain restricted pending broad user adoption of the patch (Chrome Release, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, resulting in high confidentiality, integrity, and availability impact on the affected browser process. Because exploitation is sandboxed, direct host-level compromise is constrained; however, this vulnerability could be chained with a sandbox escape to achieve full system compromise. All users running Chrome prior to 146.0.7680.178 on Windows, Mac, and Linux are at risk, as is Microsoft Edge (Chromium-based) (Feedly, Chrome Release).
cmd.exe, /bin/sh, powershell.exe, curl, wget) following PDF file opening events.%LOCALAPPDATA%\Google\Chrome\User Data\Crashpad\ on Windows or ~/.config/google-chrome/ on Linux) associated with PDF rendering activity.Google has released Chrome 146.0.7680.177 (Linux) and 146.0.7680.178 (Windows/Mac) which contain the fix; users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update once available. As a temporary workaround where immediate patching is not feasible, organizations can restrict users from opening untrusted PDF files in Chrome, configure an alternative PDF reader as the default, or use enterprise policy to block PDF rendering in the browser. Monitoring Chrome process logs for unexpected crashes related to PDF rendering can help detect exploitation attempts (Chrome Release, GitHub Advisory, Microsoft MSRC).
The Chrome stable channel update received broad coverage from security media outlets including GBHackers, The Hacker News, CyberSecurityNews, The Cyber Express, and Forbes, though most coverage focused primarily on the actively exploited CVE-2026-5281 (Use after free in Dawn) included in the same update. The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in the update, including CVE-2026-5287, could allow arbitrary code execution. Palo Alto Networks also issued an advisory (PAN-SA-2026-0004) covering the Chromium monthly vulnerability update for April 2026. Community discussion on platforms like Bluesky and Mastodon noted the large number of high-severity fixes (21 total) in this release (Chrome Release, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."