CVE-2026-5282
8.1Google · Chrome
Google Chrome contains an out of bounds read vulnerability in the WebCodecs component, allowing a remote attacker to read memory via a crafted HTML page.
Executive summary
A high severity out of bounds read vulnerability in Google Chrome allows remote attackers to access sensitive memory, posing a significant risk to user data confidentiality and browser stability.
Vulnerability
This vulnerability is an out of bounds read (CWE-125) occurring within the WebCodecs component of the browser. It allows an unauthenticated remote attacker to trigger memory disclosure by enticing a user to visit a specially crafted HTML page.
Business impact
Successful exploitation of this vulnerability can result in the unauthorized disclosure of sensitive information residing in the browser memory, potentially including user credentials, session tokens, or private data. With a CVSS score of 8.1, the flaw is classified as High severity because it allows a remote attacker to compromise data confidentiality and potentially cause application crashes, which disrupts business operations and impacts user trust.
Remediation
Immediate Action: Update all instances of Google Chrome to version 146.0.7680.178 or later to incorporate the vendor-supplied security patch.
Proactive Monitoring: Monitor endpoint security logs for unexpected browser process crashes or unusual network traffic patterns originating from the browser that might indicate exploitation attempts.
Compensating Controls: Ensure that enterprise security policies restrict access to untrusted or suspicious websites and utilize endpoint protection solutions that can detect and block malicious web content.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the High severity of this memory disclosure vulnerability and the ubiquity of Google Chrome in enterprise environments, immediate remediation is required. Administrators should prioritize the deployment of the latest browser update across all endpoints to eliminate the risk of remote memory access by unauthorized parties.