CVE-2026-5285
8.8Google · Chrome
A use after free vulnerability in the WebGL component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity use after free vulnerability in Google Chrome allows remote attackers to achieve arbitrary code execution, posing a significant risk to user systems.
Vulnerability
This is a use after free vulnerability (CWE-416) within the WebGL component. The flaw is triggered when an unauthenticated remote attacker lures a user to a specifically crafted HTML page, facilitating arbitrary code execution within the browser sandbox.
Business impact
Successful exploitation of this vulnerability allows a remote attacker to gain control over the browser environment, potentially leading to unauthorized data access, malware installation, or system compromise. With a CVSS score of 8.8, this flaw represents a significant risk to organizational endpoints, as web browsers are primary vectors for daily business operations.
Remediation
Immediate Action: Update all Google Chrome installations to version 146.0.7680.178 or later to incorporate the vendor-supplied security patch.
Proactive Monitoring: Review endpoint security logs for unusual browser crashes or unexpected child process spawning related to the Chrome executable.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious script execution originating from web browser processes.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of this vulnerability and the potential for remote code execution, organizations should treat this update with high priority. Ensure that all browser instances are updated across the enterprise environment immediately to mitigate the risk of browser-based attacks.