CVE-2026-5288: Use after free in WebView
Published Mar 23, 2026
·Updated
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Credit
Google
Affected Software
6 affected componentsFixes available
Google Chrome for Android<146.0.7680.178
Google Chrome<146.0.7680.177
146.0.7680.177
All of the following
Google Chrome<146.0.7680.177
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Mar 23, 2026
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Apr 1, 2026
CVE Published
via MITRE·04:41 AM
Data Sourced
via MITRE·04:41 AM
DescriptionWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Feb 13, 58282
Event
via FIRST·05:56 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2026-5288?
The severity of CVE-2026-5288 is classified as High.
2
How do I fix CVE-2026-5288?
To fix CVE-2026-5288, update Google Chrome on Android to version 146.0.7680.178 or later.
3
What causes the vulnerability CVE-2026-5288?
CVE-2026-5288 is caused by a use after free error in the WebView component of Google Chrome on Android.
4
Who can exploit CVE-2026-5288?
A remote attacker who has compromised the renderer process can exploit CVE-2026-5288.
5
What can an attacker potentially achieve by exploiting CVE-2026-5288?
An attacker can potentially perform a sandbox escape via a crafted HTML page by exploiting CVE-2026-5288.