CVE-2026-5278: Use after free in Web MIDI
Published Mar 6, 2026
·Updated
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Credit
c6eed09fc8b174b0f3eebedcceb1e792
Affected Software
6 affected componentsFixes available
Google Google Chrome for Android<146.0.7680.178
Google Chrome<146.0.7680.177
146.0.7680.177
All of the following
Google Chrome<146.0.7680.177
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Mar 6, 2026
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Apr 1, 2026
CVE Published
via MITRE·04:41 AM
Data Sourced
via MITRE·04:41 AM
DescriptionWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Feb 13, 58282
Event
via FIRST·06:32 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2026-5278?
The severity of CVE-2026-5278 is classified as High due to its potential for remote code execution.
2
How do I fix CVE-2026-5278?
To fix CVE-2026-5278, update Google Chrome for Android to version 146.0.7680.178 or later.
3
What type of vulnerability is CVE-2026-5278?
CVE-2026-5278 is a use after free vulnerability in the Web MIDI feature of Google Chrome on Android.
4
What can attackers do with CVE-2026-5278?
Attackers can execute arbitrary code on vulnerable devices through a specially crafted HTML page.
5
Which versions of Google Chrome for Android are affected by CVE-2026-5278?
Google Chrome for Android versions prior to 146.0.7680.178 are affected by CVE-2026-5278.