CVE-2026-2321
published 2026-02-11CVE-2026-2321: Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.25%
16.2th percentile
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 145.0.7632.75-1~deb12u1 | 145.0.7632.75-1~deb12u1 |
| chromium | chromium | >= 0 < 145.0.7632.75-1~deb13u1 | 145.0.7632.75-1~deb13u1 |
| chromium | chromium | >= 0 < 145.0.7632.45-1 | 145.0.7632.45-1 |
| debian | chromium | < chromium 145.0.7632.75-1~deb12u1 (bookworm) | chromium 145.0.7632.75-1~deb12u1 (bookworm) |
| chrome | < 145.0.7632.45 | 145.0.7632.45 | |
| chrome | >= 145.0.7632.45 < 145.0.7632.45 | 145.0.7632.45 | |
| chrome_chrome | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0003 Chromium: Monthly Vulnerability Update (March 2026)
vendor_paloalto·2026-03-11·CVSS 8.8
[HIGH] PAN-SA-2026-0003 Chromium: Monthly Vulnerability Update (March 2026)
PAN-SA-2026-0003 Chromium: Monthly Vulnerability Update (March 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_23.html https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_18.html https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_13.html https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_12.html https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_10.html CVE Summary CVE-2026-2314 Heap buffer overflow in Codecs CVE-2026-2317 Inappropriate implementation in Animation CVE
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-2321
vendor_chrome·2026-02-26·CVSS 8.8
CVE-2026-2321 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-2321
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-2321
Red Hat
chromium-browser: Use after free in Ozone
vendor_redhat·2026-02-10·CVSS 8.8
CVE-2026-2321 [HIGH] chromium-browser: Use after free in Ozone
chromium-browser: Use after free in Ozone
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
An use after free flaw was found in the Ozone component of the Chromium browser.
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Debian
CVE-2026-2321: chromium - Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote...
vendor_debian·2026·CVSS 8.8
CVE-2026-2321 [HIGH] CVE-2026-2321: chromium - Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote...
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: resolved (fixed in 145.0.7632.75-1~deb12u1)
bullseye: open
forky: resolved (fixed in 145.0.7632.45-1)
sid: resolved (fixed in 145.0.7632.45-1)
trixie: resolved (fixed in 145.0.7632.75-1~deb13u1)
GHSA
GHSA-hpj8-5pv7-f58m: Use after free in Ozone in Google Chrome prior to 145
ghsa_unreviewed·2026-02-11
CVE-2026-2321 [HIGH] CWE-416 GHSA-hpj8-5pv7-f58m: Use after free in Ozone in Google Chrome prior to 145
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2026-2321: Use after free in Ozone in Google Chrome prior to 145
osv·2026-02-11·CVSS 8.8
CVE-2026-2321 [HIGH] CVE-2026-2321: Use after free in Ozone in Google Chrome prior to 145
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-2321 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2321 [HIGH] CVE-2026-2321 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2321 :
Google Chrome vulnerability analysis and mitigation
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Source : NVD
## 8.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium
chromium-common
Sources
Chainguard Has Fix Added at: Mar 02, 2026
Debian 11 Severity HIGH No Fix Added at: Feb 1
Wiz
CVE-2026-4439 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-4439 [HIGH] CVE-2026-4439 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4439 :
Google Chrome vulnerability analysis and mitigation
Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Source : NVD
## 8.8
Score
Published March 20, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium-common-debuginfo
chromium-debuginfo
Sources
Debian 11 Severity HIGH No Fix Added at: Mar 20, 2026
Debian 12, 13, 14 Severity HIGH Has Fix Adde
Wiz
CVE-2026-5278 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5278 [HIGH] CVE-2026-5278 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5278 :
Google Chrome vulnerability analysis and mitigation
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 8.8
Score
Published April 1, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromedriver
chromium-common
Sources
Debian 11 Severity HIGH No Fix Added at: Apr 02, 2026
Debian 12, 13, 14 Severity HIGH Has Fix Added at: Apr 02, 2026
Echo Severity HIGH Has Fi
Wiz
CVE-2026-2315 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2315 [HIGH] CVE-2026-2315 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2315 :
Google Chrome vulnerability analysis and mitigation
Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 8.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cef-devel
chromium-headless-debuginfo
Sources
Alpine 3.23 Severity HIGH Has Fix Added at: Feb 20, 2026
Alpine edge Severity HIGH Has Fix Added at: Feb 1
Wiz
CVE-2026-5282 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5282 [HIGH] CVE-2026-5282 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5282 :
Google Chrome vulnerability analysis and mitigation
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 8.1
Score
Published April 1, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium-qt6-ui-debuginfo
cpe:2.3:a:google:chrome
Sources
Debian 11 Severity HIGH No Fix Added at: Apr 02, 2026
Debian 12, 13, 14 Severity HIGH Has Fix Added at: Apr 02, 20
Wiz
CVE-2026-5288 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5288 [HIGH] CVE-2026-5288 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5288 :
Google Chrome vulnerability analysis and mitigation
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 9.6
Score
Published April 1, 2026
Severity CRITICAL
CNA Score 9.6
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium-debuginfo
chromium-headless-debuginfo
Sources
Debian 11 Severity CRITICAL No Fix Added at: Apr 02, 2026
Debian 12
Bugzilla
CVE-2026-58381 gimp: gimp: Double-free in read_layer_block()
bugzilla·2026-07-01·CVSS 6.1
CVE-2026-58381 [MEDIUM] CVE-2026-58381 gimp: gimp: Double-free in read_layer_block()
CVE-2026-58381 gimp: gimp: Double-free in read_layer_block()
A double-free vulnerability exists in GIMP's Paint Shop Pro (PSP) file format parser. In read_layer_block() in file-psp.c, the variable name is allocated, used, and freed each loop iteration. On the error path in the 2nd iteration, fread fails before g_malloc for name, so the stale pointer from iteration 1 is freed again via g_free(name).
- Function: read_layer_block()
- File: plug-ins/common/file-psp.c:1908-2321
- Fix: https://gitlab.gnome.org/GNOME/gimp/-/commit/b22e147b
- Upstream issue: https://gitlab.gnome.org/GNOME/gimp/-/issues/16207
- Acknowledgment: bb1abu
2026-02-11
Published