CVE-2026-5278: Use after free in Web MIDI
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 146.0.7680.177
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-5278?
The severity of CVE-2026-5278 is classified as High due to its potential for remote code execution.
How do I fix CVE-2026-5278?
To fix CVE-2026-5278, update Google Chrome for Android to version 146.0.7680.178 or later.
What type of vulnerability is CVE-2026-5278?
CVE-2026-5278 is a use after free vulnerability in the Web MIDI feature of Google Chrome on Android.
What can attackers do with CVE-2026-5278?
Attackers can execute arbitrary code on vulnerable devices through a specially crafted HTML page.
Which versions of Google Chrome for Android are affected by CVE-2026-5278?
Google Chrome for Android versions prior to 146.0.7680.178 are affected by CVE-2026-5278.