CVE-2026-5285 is a high-severity use-after-free vulnerability in WebGL affecting Google Chrome versions prior to 146.0.7680.178, impacting users on Apple, Google, Linux, and Microsoft platforms. This flaw allows a remote attacker to achieve arbitrary code execution within the browser's sandbox by tricking a user into visiting a specially crafted HTML page. With a CVSS score of 8.8 (High), it presents a significant risk to confidentiality, integrity, and availability if exploited. The attack requires user interaction but has low complexity. While not currently listed on CISA's KEV catalog and lacking public exploit code, it is on an active "Hot List" and has garnered some community discussion and media coverage, indicating its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.178, < 146.0.7680.178CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.177CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.