
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5288 is a use-after-free vulnerability in WebView in Google Chrome on Android that allows a remote attacker who has already compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. The vulnerability was reported by Google's internal security team on March 23, 2026, and publicly disclosed on March 31, 2026, as part of a stable channel update. It affects Google Chrome on Android prior to version 146.0.7680.178. It carries a CVSS v3.1 base score of 9.6 (Critical) (Chrome Releases, Github Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), occurring within the WebView component of Google Chrome on Android (Github Advisory). A use-after-free flaw arises when memory is freed but a dangling pointer to that memory region is subsequently dereferenced, potentially allowing an attacker to control program execution by manipulating heap memory layout. Exploitation requires that the attacker has already compromised the Chrome renderer process; from that position, a crafted HTML page can trigger the use-after-free condition in WebView to escape the browser sandbox. The bug was tracked internally as Chromium issue 495507390 and was reported by Google's own security team, suggesting it may have been discovered through internal fuzzing or security review (Chrome Releases, Red Hat Bugzilla).
Successful exploitation allows an attacker who has already compromised the Chrome renderer process to escape the browser sandbox on Android devices, potentially gaining elevated privileges on the underlying system. This could lead to complete device compromise, including unauthorized access to sensitive user data, installation of malware, and lateral movement within the affected device or connected systems. The scope change reflected in the CVSS score (S:C) underscores that the impact extends beyond the browser process itself to the broader Android operating system (Github Advisory, Red Hat Bugzilla).
logcat) showing crashes or anomalous memory access errors in the WebView or Chrome renderer process; repeated WebView crashes followed by unusual process activity.Google has released a patch in Chrome version 146.0.7680.178 for Android (and 146.0.7680.177/178 for Windows/Mac/Linux), which addresses CVE-2026-5288 along with 20 other security fixes (Chrome Releases). Users and administrators should update Google Chrome on all Android devices to version 146.0.7680.178 or later immediately. Organizations should use Mobile Device Management (MDM) solutions to enforce Chrome version requirements and monitor for outdated browser versions across managed devices. As a general precaution, limit WebView-based applications' access to untrusted HTML content and avoid browsing to unknown or suspicious websites until the update is applied.
The Chrome stable channel update that included CVE-2026-5288 received broad coverage from security media, primarily due to the co-disclosed CVE-2026-5281 (Use after free in Dawn), for which Google confirmed active in-the-wild exploitation. Coverage from GBHackers, CyberSecurityNews, CyberPress, The Hacker News, and Forbes highlighted the update as an emergency patch for Chrome zero-days, with some outlets framing it as the fourth Chrome zero-day of 2026 (GBHackers, The Hacker News, Forbes). The CIS also issued an advisory noting multiple vulnerabilities in Google Chrome that could allow arbitrary code execution (CIS Advisory). CVE-2026-5288 itself was not singled out as actively exploited in any public reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."