CVE-2026-5290 is a high-severity use-after-free vulnerability (CWE-416) in Google Chrome's Compositing component, affecting versions prior to 146.0.7680.178. This flaw allows a remote attacker, after compromising the renderer process, to potentially achieve a sandbox escape through a crafted HTML page, indicating a significant impact despite requiring an initial compromise. There is currently no evidence of active exploitation, no public exploit code available on platforms like Metasploit or ExploitDB, and minimal community discussion beyond its recent publication.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.178, < 146.0.7680.178CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.177CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.