CVE-2026-5292

8.8

Google · Chrome

A remote attacker can perform an out of bounds memory read in Google Chrome via a crafted HTML page due to a flaw in WebCodecs.

Executive summary

An out of bounds read vulnerability in Google Chrome allows remote attackers to access sensitive memory via malicious web content, posing a significant risk of data exposure.

Vulnerability

This vulnerability is an out of bounds read (CWE-125) located in the WebCodecs component, which can be triggered by an unauthenticated remote attacker through a crafted HTML page.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting a high potential for impact on confidentiality, integrity, and availability. Successful exploitation could allow an attacker to read arbitrary memory contents, potentially leading to the disclosure of sensitive information such as browser session data or credentials, which could facilitate further unauthorized access or system compromise.

Remediation

Immediate Action: Update Google Chrome to version 146.0.7680.178 or later immediately to incorporate the vendor-supplied security fixes.

Proactive Monitoring: Security teams should monitor endpoint logs for unusual browser crashes or unexpected behavior that may indicate attempts to trigger memory corruption vulnerabilities.

Compensating Controls: Ensure that browser security settings are strictly enforced via Group Policy or MDM and consider deploying endpoint protection platforms that can detect and block malicious web-based content.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the severity of this memory-based vulnerability, organizations should prioritize the deployment of the Chrome update across all managed workstations. Timely patching is the most effective method to neutralize this risk, as memory corruption flaws are frequently targeted for exploitation in browser-based attacks.

More Google CVEs

Sources