
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5291 is an inappropriate implementation vulnerability in the WebGL component of Google Chrome that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.178 (Windows/Mac) and 146.0.7680.177 (Linux), as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher heapracer (@heapracer) on March 6, 2026, and publicly disclosed on March 31, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), stemming from an inappropriate implementation in Chrome's WebGL subsystem. The flaw allows a remote attacker to craft a malicious HTML page that, when rendered by the browser, triggers the WebGL implementation to inadvertently expose data from the Chrome process memory. Exploitation requires user interaction — specifically, a victim visiting a malicious or compromised webpage — but requires no special privileges from the attacker. The Chromium bug tracker references issue #490118036 for this vulnerability, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation results in a high confidentiality impact, with no effect on integrity or availability. An attacker can extract potentially sensitive data from the Chrome browser's process memory — which may include credentials, session tokens, or other in-memory data — without requiring any elevated privileges. The scope is limited to the affected browser process, and there is no direct path to lateral movement or code execution from this vulnerability alone, though leaked memory contents could facilitate further attacks (GitHub Advisory, Feedly).
Google has released a patch in Chrome stable channel version 146.0.7680.177/178 (Windows/Mac: 146.0.7680.178; Linux: 146.0.7680.177), which addresses CVE-2026-5291 along with 20 other security fixes. Users and organizations should update Google Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge (Chromium-based) users should also apply the corresponding Microsoft security update. Organizations should ensure automated patch deployment is in place for browser updates to minimize exposure windows (Chrome Releases, Microsoft Advisory).
The March 31, 2026 Chrome stable update received broad coverage primarily due to the co-patched CVE-2026-5281 zero-day (Use after free in Dawn), which Google confirmed was actively exploited in the wild. Security outlets including GBHackers, CyberPress, The Hacker News, Forbes, and CyberNoz covered the update, though their focus was predominantly on CVE-2026-5281 rather than CVE-2026-5291 specifically. The CIS issued an advisory noting multiple vulnerabilities in the update could allow for arbitrary code execution. CVE-2026-5291 itself, rated Medium severity, received comparatively limited individual attention given its information-disclosure-only impact and lack of active exploitation (Chrome Releases, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."