
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5289 is a use-after-free vulnerability in the Navigation component of Google Chrome that allows a remote attacker who has already compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.178 (Windows/Mac) and 146.0.7680.177 (Linux), as well as Microsoft Edge (Chromium-based). The vulnerability was reported to Google by an internal Google researcher on March 25, 2026, and publicly disclosed on March 31, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 9.6 (Critical) (Chrome Releases, GitHub Advisory, Red Hat).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), occurring in Chrome's Navigation component when memory is accessed after being freed (GitHub Advisory, Red Hat Bugzilla). Exploitation requires that an attacker has already compromised the renderer process — typically through a separate renderer vulnerability — and then leverages this use-after-free to escape Chrome's sandbox by delivering a crafted HTML page to the victim. The attack vector is network-based, requires no privileges, and requires user interaction (e.g., visiting a malicious page), but the scope change (sandbox escape) elevates its severity significantly. The Chromium issue tracker entry is https://issues.chromium.org/issues/495931147, though details remain restricted pending broad user patching (Chrome Releases).
Successful exploitation allows a remote attacker who has compromised the renderer process to escape Chrome's sandbox and execute arbitrary code on the underlying host system with the privileges of the browser process. This can result in full confidentiality, integrity, and availability compromise — including unauthorized access to system resources, sensitive data theft, installation of malware, and potential lateral movement within the victim's environment. The changed scope (S:C) in the CVSS score reflects that the impact extends beyond the browser sandbox to the host operating system (GitHub Advisory, Red Hat Bugzilla).
cmd.exe, powershell.exe, bash, curl, wget) that are not typical renderer or GPU helper processes.chrome.exe --type=renderer) spawning network connections or file system writes outside of expected browser cache/profile directories.execve audit events with chrome as parent.chrome://crashes) which may indicate failed exploitation attempts.Google has released a patch in Chrome stable channel version 146.0.7680.177 (Linux) and 146.0.7680.178 (Windows/Mac); users should update immediately via Chrome's built-in updater or by downloading from the official Chrome website (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update addressing CVE-2026-5289 (Microsoft MSRC). Organizations should prioritize patching given the sandbox escape capability and high CVSS score; as a temporary measure, users should avoid visiting untrusted or unfamiliar websites until the update is applied. Enterprise administrators can use group policy or fleet management tools to force-update Chrome across managed endpoints.
The broader Chrome stable update (146.0.7680.177/178) received significant media attention primarily due to CVE-2026-5281, which was confirmed exploited in the wild; CVE-2026-5289 was covered as part of the same patch batch (GBHackers, The Hacker News). Security outlets including SecurityOnline, CyberPress, and CyberSecurityNews reported on the Chrome zero-day update, with coverage noting the sandbox escape potential of CVE-2026-5289 alongside the actively exploited CVE-2026-5281 (The Hacker Wire). Forbes highlighted the update as a zero-day attack alert for Chrome's 3.5 billion users, underscoring the urgency of patching (Forbes). The CIS also issued an advisory noting multiple Chrome vulnerabilities in this update could allow arbitrary code execution (CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."