CVE-2026-5286

8.8

Google · Chrome

A use after free vulnerability in the Dawn component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code, posing a significant risk to user systems.

Vulnerability

This is a use after free vulnerability within the Dawn component. It can be triggered by an unauthenticated remote attacker who lures a user to a crafted HTML page to achieve arbitrary code execution.

Business impact

The ability for a remote attacker to execute arbitrary code on a user's machine creates a substantial risk of system compromise, data theft, and malware installation. With a CVSS score of 8.8, this vulnerability represents a high risk to organizational security, particularly for environments where browser-based threats are prevalent.

Remediation

Immediate Action: Update all instances of Google Chrome to version 146.0.7680.178 or later to incorporate the vendor-supplied security patch.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or processes spawned by the Chrome application.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious code execution attempts originating from web browser processes.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution and the high severity of this flaw, security teams must prioritize the deployment of the latest Chrome updates across all managed endpoints. Failure to patch this vulnerability leaves systems susceptible to exploitation through standard web browsing activities, necessitating immediate action.

More Google CVEs

Sources