CVE-2026-5286
8.8Google · Chrome
A use after free vulnerability in the Dawn component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code, posing a significant risk to user systems.
Vulnerability
This is a use after free vulnerability within the Dawn component. It can be triggered by an unauthenticated remote attacker who lures a user to a crafted HTML page to achieve arbitrary code execution.
Business impact
The ability for a remote attacker to execute arbitrary code on a user's machine creates a substantial risk of system compromise, data theft, and malware installation. With a CVSS score of 8.8, this vulnerability represents a high risk to organizational security, particularly for environments where browser-based threats are prevalent.
Remediation
Immediate Action: Update all instances of Google Chrome to version 146.0.7680.178 or later to incorporate the vendor-supplied security patch.
Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or processes spawned by the Chrome application.
Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious code execution attempts originating from web browser processes.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution and the high severity of this flaw, security teams must prioritize the deployment of the latest Chrome updates across all managed endpoints. Failure to patch this vulnerability leaves systems susceptible to exploitation through standard web browsing activities, necessitating immediate action.