CVE-2026-5288: Use after free in WebView
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 146.0.7680.177
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-5288?
The severity of CVE-2026-5288 is classified as High.
How do I fix CVE-2026-5288?
To fix CVE-2026-5288, update Google Chrome on Android to version 146.0.7680.178 or later.
What causes the vulnerability CVE-2026-5288?
CVE-2026-5288 is caused by a use after free error in the WebView component of Google Chrome on Android.
Who can exploit CVE-2026-5288?
A remote attacker who has compromised the renderer process can exploit CVE-2026-5288.
What can an attacker potentially achieve by exploiting CVE-2026-5288?
An attacker can potentially perform a sandbox escape via a crafted HTML page by exploiting CVE-2026-5288.