CVE-2026-5278

8.8

Google · Chrome

A use after free vulnerability in the Web MIDI component of Google Chrome for Android allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome for Android enables remote code execution when a user visits a malicious website.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Web MIDI implementation. The flaw allows an unauthenticated remote attacker to achieve arbitrary code execution by enticing a user to navigate to a specifically crafted HTML page.

Business impact

Successful exploitation of this vulnerability could lead to a full compromise of the user device. Given the CVSS score of 8.8, this represents a significant risk to data confidentiality, integrity, and system availability. Unauthorized code execution in a browser context frequently serves as a gateway for further lateral movement or the theft of sensitive session data.

Remediation

Immediate Action: Update Google Chrome for Android to version 146.0.7680.178 or later via the Google Play Store.

Proactive Monitoring: Monitor device or network logs for unusual browser activity or unexpected crashes that may indicate exploitation attempts.

Compensating Controls: Ensure that browser security settings are configured to restrict site permissions and consider using mobile device management (MDM) policies to enforce timely browser updates across the enterprise.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability poses a severe risk due to the potential for remote code execution. Security teams should prioritize updating all instances of Google Chrome on Android devices to the patched version immediately to prevent potential exploitation.

More Google CVEs

Sources