Integer Overflow Vulnerability in Google Chrome for Windows
CVE-2026-5277

7.5HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-5277?

An integer overflow vulnerability exists in the ANGLE component of Google Chrome for Windows. This flaw can be exploited remotely by an attacker who has taken control of the renderer process, allowing for an out-of-bounds memory write when a user interacts with a specially crafted HTML page. As a result, this could potentially lead to unauthorized code execution or data corruption within the affected browser versions.

Affected Version(s)

Chrome 146.0.7680.178

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.