Use After Free Vulnerability in Google Chrome Navigation Process
CVE-2026-5289

9.6CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-5289?

A use after free vulnerability in the navigation component of Google Chrome has been identified. This flaw exists in versions prior to 146.0.7680.178 and poses a risk of sandbox escape for remote attackers who compromise the renderer process. By crafting a specially-designed HTML page, an attacker may exploit this vulnerability to execute unauthorized actions within the browser's context, potentially leading to further security breaches. Users are advised to update their browser to mitigate this risk.

Affected Version(s)

Chrome 146.0.7680.178

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.