CVE-2026-5292
vulnerability analysis and mitigation

Overview

CVE-2026-5292 is an out-of-bounds read vulnerability in the WebCodecs component of Google Chrome, allowing a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. It was reported internally by Google on March 12, 2026, and publicly disclosed on March 31, 2026, as part of a stable channel update. The vulnerability affects Google Chrome versions prior to 146.0.7680.178 (Windows/Mac) and 146.0.7680.177 (Linux), as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's WebCodecs API, which provides low-level access to media encoding and decoding functionality. An attacker can exploit this flaw by crafting a malicious HTML page that triggers the WebCodecs component to read memory beyond the intended buffer boundaries. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page using a vulnerable Chrome version. The Chromium issue tracker entry is #492213293, though full technical details remain restricted pending broad patch deployment (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation could expose sensitive data from the browser's memory, including credentials, session tokens, or other confidential information processed by the browser. The CVSS scoring reflects high impacts to confidentiality, integrity, and availability, suggesting that while the primary risk is information disclosure, memory corruption side effects could potentially enable further exploitation. The vulnerability affects all major desktop platforms (Windows, macOS, Linux) running unpatched Chrome, as well as Chromium-based browsers such as Microsoft Edge (GitHub Advisory, Red Hat Bugzilla).

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 146.0.7680.177/178 (Windows/Mac: 146.0.7680.178; Linux: 146.0.7680.177). Users and administrators should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or through enterprise deployment tools. Enabling automatic updates is strongly recommended to ensure timely patching. As a temporary measure until patching is complete, organizations should consider restricting access to untrusted or unknown websites and implementing web content filtering. Microsoft Edge users should also apply the corresponding Chromium-based Edge update (Chrome Releases, Microsoft MSRC).

Community reactions

The March 31, 2026 Chrome update attracted significant media attention primarily due to the co-patched CVE-2026-5281 zero-day being actively exploited in the wild, with outlets such as GBHackers, The Hacker News, Forbes, and CyberPress covering the release under headlines referencing a Chrome zero-day. CVE-2026-5292 received secondary coverage as part of the broader 21-fix update. The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in this Chrome update could allow for arbitrary code execution (CIS Advisory). Security vendors including Qualys, Tenable/Nessus, Palo Alto Networks, and Red Hat tracked and published detection content for the vulnerability (Red Hat Bugzilla).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management