CVE-2026-5278
published 2026-04-01CVE-2026-5278: Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page…
PriorityP351high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.41%
33.3th percentile
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 146.0.7680.177-1~deb12u1 | 146.0.7680.177-1~deb12u1 |
| chromium | chromium | >= 0 < 146.0.7680.177-1~deb13u1 | 146.0.7680.177-1~deb13u1 |
| chromium | chromium | >= 0 < 146.0.7680.177-1 | 146.0.7680.177-1 |
| debian | chromium | < chromium 146.0.7680.177-1~deb12u1 (bookworm) | chromium 146.0.7680.177-1~deb12u1 (bookworm) |
| chrome | < 146.0.7680.177 | 146.0.7680.177 | |
| chrome | >= 146.0.7680.178 < 146.0.7680.178 | 146.0.7680.178 | |
| chrome_chrome | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
vendor_paloalto·2026-05-13·CVSS 8.8
CVE-2026-4439 [HIGH] PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_22.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html CVE Summary CVE-2026-4439 Out of bounds memory access in WebGL CVE-2026-4440 Out of bounds read and write in WebGL CVE-2026-4441 Use after free in Base CVE-2026-4442 Heap buffer overflow in
Chrome
Stable Channel Update for Desktop: CVE-2026-5278
vendor_chrome·2026-03-31·CVSS 8.8
CVE-2026-5278 [HIGH] Stable Channel Update for Desktop: CVE-2026-5278
Stable Channel Update for Desktop
CVE-2026-5278: Use after free in Web MIDI. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-06 [TBD][ 490642836 ] High CVE-2026-5279: Object corruption in V8
Reported by Hyeonjun Ahn (@_deayzl) on 2026-03-08 [TBD][ 491515787 ] High CVE-2026-5280: Use after free in WebCodecs
Severity: high
Red Hat
chromium-browser: Use after free in Web MIDI
vendor_redhat·2026-03-31·CVSS 8.8
CVE-2026-5278 [HIGH] CWE-825 chromium-browser: Use after free in Web MIDI
chromium-browser: Use after free in Web MIDI
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
An use after free flaw was found in the Web MIDI component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=490254128
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Debian
CVE-2026-5278: chromium - Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 a...
vendor_debian·2026·CVSS 8.8
CVE-2026-5278 [HIGH] CVE-2026-5278: chromium - Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 a...
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 146.0.7680.177-1)
trixie: resolved (fixed in 146.0.7680.177-1~deb13u1)
OSV
CVE-2026-5278: Use after free in Web MIDI in Google Chrome on Android prior to 146
osv·2026-04-01·CVSS 8.8
CVE-2026-5278 [HIGH] CVE-2026-5278: Use after free in Web MIDI in Google Chrome on Android prior to 146
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
GHSA
GHSA-63vg-wchr-j5wj: Use after free in Web MIDI in Google Chrome on Android prior to 146
ghsa_unreviewed·2026-04-01
CVE-2026-5278 [HIGH] CWE-416 GHSA-63vg-wchr-j5wj: Use after free in Web MIDI in Google Chrome on Android prior to 146
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0943 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-0943 [HIGH] CVE-2026-0943 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0943 :
Linux Fedora vulnerability analysis and mitigation
HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.
Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.
Source : NVD
## 7.5
Score
Published January 19, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 34.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
perl-HarfBuzz-Shaper
perl-HarfBuzz-Shaper-debuginfo
Sources
NVD
## Get a CVE risk assessment
Get a prioritized vi
Wiz
CVE-2026-29022 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-29022 [MEDIUM] CVE-2026-29022 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-29022 :
Linux Fedora vulnerability analysis and mitigation
dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.
Source : NVD
## 6.8
Score
Published March 3, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Linux Fedora
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Prob
Wiz
CVE-2026-25554 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.3
CVE-2026-25554 [HIGH] CVE-2026-25554 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25554 :
Linux Fedora vulnerability analysis and mitigation
OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vulnerability in the jwt_db_authorize() function in modules/auth_jwt/authorize.c when db_mode is enabled and a SQL database backend is used. The function extracts the tag claim from a JWT without prior signature verification and incorporates the unescaped value directly into a SQL query. An attacker can supply a crafted JWT with a malicious tag claim to manipulate the query result and bypass JWT authentication, allowing impersonation of arbitrary identities.
Source : NVD
## 8.3
Score
Published February 25, 2026
Severity HIGH
CNA Score 8.3
Affected Technologies
Linux Fedora
Has Public Exploit Y
Wiz
CVE-2026-2321 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2321 [HIGH] CVE-2026-2321 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2321 :
Google Chrome vulnerability analysis and mitigation
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Source : NVD
## 8.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium
chromium-common
Sources
Chainguard Has Fix Added at: Mar 02, 2026
Debian 11 Severity HIGH No Fix Added at: Feb 1
Wiz
CVE-2026-24480 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-24480 [HIGH] CVE-2026-24480 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24480 :
Linux Fedora vulnerability analysis and mitigation
pull_request_target
pull_request_target
Source : NVD
## 8.7
Score
Published January 27, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Linux Fedora
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 61.8
Exploitation Probability (EPSS) 0.4
Affected packages and libraries
qgis-server
qgis-server-debuginfo
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related Linux Fedora vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026
Wiz
CVE-2026-4439 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-4439 [HIGH] CVE-2026-4439 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4439 :
Google Chrome vulnerability analysis and mitigation
Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Source : NVD
## 8.8
Score
Published March 20, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium-common-debuginfo
chromium-debuginfo
Sources
Debian 11 Severity HIGH No Fix Added at: Mar 20, 2026
Debian 12, 13, 14 Severity HIGH Has Fix Adde
Wiz
CVE-2026-5278 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5278 [HIGH] CVE-2026-5278 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5278 :
Google Chrome vulnerability analysis and mitigation
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 8.8
Score
Published April 1, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromedriver
chromium-common
Sources
Debian 11 Severity HIGH No Fix Added at: Apr 02, 2026
Debian 12, 13, 14 Severity HIGH Has Fix Added at: Apr 02, 2026
Echo Severity HIGH Has Fi
Wiz
CVE-2026-2315 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2315 [HIGH] CVE-2026-2315 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2315 :
Google Chrome vulnerability analysis and mitigation
Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 8.8
Score
Published February 11, 2026
Severity HIGH
CNA Score 8.8
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cef-devel
chromium-headless-debuginfo
Sources
Alpine 3.23 Severity HIGH Has Fix Added at: Feb 20, 2026
Alpine edge Severity HIGH Has Fix Added at: Feb 1
Wiz
CVE-2026-5282 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5282 [HIGH] CVE-2026-5282 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5282 :
Google Chrome vulnerability analysis and mitigation
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 8.1
Score
Published April 1, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium-qt6-ui-debuginfo
cpe:2.3:a:google:chrome
Sources
Debian 11 Severity HIGH No Fix Added at: Apr 02, 2026
Debian 12, 13, 14 Severity HIGH Has Fix Added at: Apr 02, 20
Wiz
CVE-2025-69217 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.7
CVE-2025-69217 [HIGH] CVE-2025-69217 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69217 :
Linux Fedora vulnerability analysis and mitigation
coturn is a free open source implementation of TURN and STUN Server. Versions 4.6.2r5 through 4.7.0-r4 have a bad random number generator for nonces and port randomization after refactoring. Additionally, random numbers aren't generated with openssl's RAND_bytes but libc's random() (if it's not running on Windows). When fetching about 50 sequential nonces (i.e., through sending 50 unauthenticated allocations requests) it is possible to completely reconstruct the current state of the random number generator, thereby predicting the next nonce. This allows authentication while spoofing IPs. An attacker can send authenticated messages without ever receiving the responses, including the nonce (requires knowledge of the cre
Wiz
CVE-2026-5288 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5288 [HIGH] CVE-2026-5288 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5288 :
Google Chrome vulnerability analysis and mitigation
Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 9.6
Score
Published April 1, 2026
Severity CRITICAL
CNA Score 9.6
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium-debuginfo
chromium-headless-debuginfo
Sources
Debian 11 Severity CRITICAL No Fix Added at: Apr 02, 2026
Debian 12
Bugzilla
CVE-2026-5278 chromium: Use after free in Web MIDI [epel-all]
bugzilla·2026-04-01·CVSS 8.8
CVE-2026-5278 [HIGH] CVE-2026-5278 chromium: Use after free in Web MIDI [epel-all]
CVE-2026-5278 chromium: Use after free in Web MIDI [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
It's fixed in https://bodhi.fedoraproject.org/updates/?search=chromium-146.0.7680.177
Bugzilla
CVE-2026-5278 chromium: Use after free in Web MIDI [fedora-all]
bugzilla·2026-04-01·CVSS 8.8
CVE-2026-5278 [HIGH] CVE-2026-5278 chromium: Use after free in Web MIDI [fedora-all]
CVE-2026-5278 chromium: Use after free in Web MIDI [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
It's fixed in https://bodhi.fedoraproject.org/updates/?search=chromium-146.0.7680.177
2026-04-01
Published