CVE-2026-5280
published 2026-04-01CVE-2026-5280: Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.40%
32.2th percentile
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chromium | chromium | >= 0 < 146.0.7680.177-1~deb12u1 | 146.0.7680.177-1~deb12u1 |
| chromium | chromium | >= 0 < 146.0.7680.177-1~deb13u1 | 146.0.7680.177-1~deb13u1 |
| chromium | chromium | >= 0 < 146.0.7680.177-1 | 146.0.7680.177-1 |
| cryptography.io | cryptography | >= 0 < 46.0.6 | 46.0.6 |
| debian | chromium | < chromium 146.0.7680.177-1~deb12u1 (bookworm) | chromium 146.0.7680.177-1~deb12u1 (bookworm) |
| chrome | < 146.0.7680.177 | 146.0.7680.177 | |
| chrome | >= 146.0.7680.178 < 146.0.7680.178 | 146.0.7680.178 | |
| chrome_chrome | — | — | |
| msrc | microsoft_edge | — | — |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa6.5MEDIUM
osv8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
vendor_paloalto·2026-05-13·CVSS 8.8
CVE-2026-4439 [HIGH] PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_22.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html CVE Summary CVE-2026-4439 Out of bounds memory access in WebGL CVE-2026-4440 Out of bounds read and write in WebGL CVE-2026-4441 Use after free in Base CVE-2026-4442 Heap buffer overflow in
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2026-5280
vendor_chrome·2026-04-17
CVE-2026-5280 Long Term Support Channel Update for ChromeOS: CVE-2026-5280
Long Term Support Channel Update for ChromeOS
CVE-2026-5280
Microsoft
Chromium: CVE-2026-5280 Use after free in WebCodecs
vendor_msrc·2026-04-02·CVSS 8.8
CVE-2026-5280 [HIGH] Chromium: CVE-2026-5280 Use after free in WebCodecs
Chromium: CVE-2026-5280 Use after free in WebCodecs
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Microsoft Edge browser, click on the 3 dots (...) on the very right-hand side of the window
Click on Help and Feedback
Click on About Microsoft Edge
FAQ: W
Chrome
Stable Channel Update for Desktop: CVE-2026-5278
vendor_chrome·2026-03-31·CVSS 8.8
CVE-2026-5278 [HIGH] Stable Channel Update for Desktop: CVE-2026-5278
Stable Channel Update for Desktop
CVE-2026-5278: Use after free in Web MIDI. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-06 [TBD][ 490642836 ] High CVE-2026-5279: Object corruption in V8
Reported by Hyeonjun Ahn (@_deayzl) on 2026-03-08 [TBD][ 491515787 ] High CVE-2026-5280: Use after free in WebCodecs
Severity: high
Red Hat
chromium-browser: Use after free in WebCodecs
vendor_redhat·2026-03-31·CVSS 8.8
CVE-2026-5280 [HIGH] CWE-825 chromium-browser: Use after free in WebCodecs
chromium-browser: Use after free in WebCodecs
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
An use after free flaw was found in the WebCodecs component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=491515787
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Red Hat
node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance
vendor_redhat·2026-03-27·CVSS 7.4
CVE-2026-33896 [HIGH] CWE-295 node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance
node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.
A flaw was found in Forge (also known as node-forge), a JavaScript implementation of Transport Layer Security (TLS). The `pki.verifyCertificateChain()` function does not properly enforce certificate validation r
Debian
CVE-2026-5280: chromium - Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a r...
vendor_debian·2026·CVSS 8.8
CVE-2026-5280 [HIGH] CVE-2026-5280: chromium - Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a r...
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: resolved (fixed in 146.0.7680.177-1~deb12u1)
bullseye: open
forky: resolved (fixed in 146.0.7680.177-1)
sid: resolved (fixed in 146.0.7680.177-1)
trixie: resolved (fixed in 146.0.7680.177-1~deb13u1)
GHSA
GHSA-rxr9-x3w7-wrh7: Use after free in WebCodecs in Google Chrome prior to 146
ghsa_unreviewed·2026-04-01
CVE-2026-5280 [MEDIUM] CWE-416 GHSA-rxr9-x3w7-wrh7: Use after free in WebCodecs in Google Chrome prior to 146
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
OSV
CVE-2026-5280: Use after free in WebCodecs in Google Chrome prior to 146
osv·2026-04-01·CVSS 8.8
CVE-2026-5280 [HIGH] CVE-2026-5280: Use after free in WebCodecs in Google Chrome prior to 146
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
GHSA
cryptography has incomplete DNS name constraint enforcement on peer names
ghsa·2026-03-27·CVSS 6.5
CVE-2026-34073 [MEDIUM] CWE-295 cryptography has incomplete DNS name constraint enforcement on peer names
cryptography has incomplete DNS name constraint enforcement on peer names
## Summary
In versions of cryptography prior to 46.0.5, DNS name constraints were only validated against SANs within child certificates, and not the "peer name" presented during each validation. Consequently, cryptography would allow a peer named `bar.example.com` to validate against a wildcard leaf certificate for `*.example.com`, even if the leaf's parent certificate (or upwards) contained an excluded subtree constraint for `bar.example.com`.
This behavior resulted from a gap between RFC 5280 (which defines Name Constraint semantics) and RFC 9525 (which defines service identity semantics): put together, neither states definitively whether Name Constraints should be applied to peer names. To close this gap, crypt
GHSA
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
ghsa·2026-03-26
CVE-2026-33896 [HIGH] CWE-295 Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
## Summary
`pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid.
## Technical Details
In `lib/x509.js`, the `verifyCertificateChain()` function (around lines 3147-3199) has two conditional checks for CA authorization:
1. The `keyUsage` check (which includes a sub-check requiring `basicConstraints` to be present) is gated on `keyUsageExt !== null`
2. The `basicConstraints.cA` check is gated on `bcExt !== null`
When a certifica
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42790 erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing
bugzilla·2026-05-27·CVSS 8.1
CVE-2026-42790 [HIGH] CVE-2026-42790 erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing
CVE-2026-42790 erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification.
Two flaws combine to allow a subordinate CA whose DNS nameConstraints are restricted (e.g. permitted;DNS:allowed.example.com) to issue a leaf certificate that an OTP TLS client accepts as a valid identity for an out-of-scope hostname (e.g. victim.example.com):
First, pubkey_cert:validate_names/6 in lib/public_key/src/pubkey_cert.erl only checks SAN DNS entries against nameConstraints. Per RFC 5280, a permitted DNS subtree only restricts certificates that contain a DNS-typed name. A lea
Bugzilla
CVE-2026-5280 chromium: Use after free in WebCodecs [epel-all]
bugzilla·2026-04-01·CVSS 8.8
CVE-2026-5280 [HIGH] CVE-2026-5280 chromium: Use after free in WebCodecs [epel-all]
CVE-2026-5280 chromium: Use after free in WebCodecs [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
It's fixed in https://bodhi.fedoraproject.org/updates/?search=chromium-146.0.7680.177
Bugzilla
CVE-2026-5280 chromium: Use after free in WebCodecs [fedora-all]
bugzilla·2026-04-01·CVSS 8.8
CVE-2026-5280 [HIGH] CVE-2026-5280 chromium: Use after free in WebCodecs [fedora-all]
CVE-2026-5280 chromium: Use after free in WebCodecs [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
It's fixed in https://bodhi.fedoraproject.org/updates/?search=chromium-146.0.7680.177
Bugzilla
CVE-2026-32884 Botan: Botan: Certificate validation bypass due to mixed-case Common Name in X.509 certificates
bugzilla·2026-03-30·CVSS 5.9
CVE-2026-32884 [MEDIUM] CVE-2026-32884 Botan: Botan: Certificate validation bypass due to mixed-case Common Name in X.509 certificates
CVE-2026-32884 Botan: Botan: Certificate validation bypass due to mixed-case Common Name in X.509 certificates
Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict the set of allowable DNS names, if no subject alternative name is defined in the end-entity certificate Botan would check that the CN was allowed by the DNS name constraints, even though this check is technically not required by RFC 5280. However this check failed to account for the possibility of a mixed-case CN. Thus a certificate with CN=Sub.EVIL.COM and no subject alternative name would bypasses an excludedSubtrees constraint for evil.com because the comparison is case-sensitive. This issue has been patched in version 3.11.0.
Bugzilla
CVE-2026-33896 node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance
bugzilla·2026-03-27·CVSS 9.1
CVE-2026-33896 [CRITICAL] CVE-2026-33896 node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance
CVE-2026-33896 node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstraints` and `keyUsage` extensions. This allows any leaf certificate (without these extensions) to act as a CA and sign other certificates, which node-forge will accept as valid. Version 1.4.0 patches the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Ansible Automation Platform 2.5 for RHEL 9
Red Hat Ansible Automation Platform 2.5 for RHEL 8
Via RHSA-2026:24761 ht
Sans Isc
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
blogs_sans_isc·2026-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026.
Published: 2026-04-14. Last Updated: 2026-04-14 17:46:09 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month's Microsoft Patch Tuesday looks like a record one, but let's look at it a bit closer to understand what is happening
The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.
Noteworthy Vulnerabilities:
CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love thes
Wiz
CVE-2026-5280 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5280 [HIGH] CVE-2026-5280 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5280 :
vulnerability analysis and mitigation
Use after free in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Source : NVD
## 8.8
Score
Published April 1, 2026
Severity HIGH
CNA Score 8.8
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium-qt5-ui
chromium-qt5-ui-debuginfo
Sources
Debian 11 Severity HIGH No Fix Added at: Apr 02, 2026
Debian 12, 13, 14 Severity HIGH Has Fix Added at: Apr 02, 2026
Echo Severity HIGH Has Fix Added at: Apr 02, 2026
Nix Severity HIG
2026-04-01
Published