CVE-2026-5292 identifies an out of bounds read vulnerability within the WebCodecs component of Google Chrome, affecting versions prior to 146.0.7680.178. A remote attacker could exploit this by enticing a user to visit a specially crafted HTML page, potentially leading to an out of bounds memory read and information disclosure. Chromium has assigned this a Medium severity rating. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.178, < 146.0.7680.178CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.177CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.