CVE-2026-5291 describes a medium-severity information disclosure vulnerability in Google Chrome versions prior to 146.0.7680.178, stemming from an inappropriate WebGL implementation. A remote attacker could exploit this flaw by enticing a user to visit a crafted HTML page, potentially allowing the retrieval of sensitive information from the browser's process memory. There is currently no evidence of active exploitation, nor are there any public exploit modules or proof-of-concept code available. While not on the CISA KEV list and lacking media coverage, the vulnerability has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.178, < 146.0.7680.178CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.177CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.