Description
Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published: 2026-04-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

The vulnerability is a heap buffer overflow in the GPU component of Google Chrome. A crafted HTML page can trigger a memory corruption that allows a remote attacker to execute arbitrary code, potentially taking full control of the affected system. The weakness is identified as CWE‑120 and CWE‑122, reflecting buffer copy without size checking and heap buffer overflow respectively. Chrome categorized the issue as high severity because it can compromise confidentiality, integrity, and availability on the victim host.

Affected Systems

The flaw affects Google Chrome versions prior to 146.0.7680.178 on all supported operating systems—Windows, macOS, and Linux—since the vulnerability resides in a cross‑platform GPU subsystem. Users running a vulnerable build of Chrome on any of these platforms are at risk.

Risk and Exploitability

The CVSS score of 8.8 indicates a high potential impact, while the EPSS score of less than 1 % reflects a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread active exploitation. Attackers would need to lure users to a malicious web page containing carefully crafted content; the attack is remote, network‑based, and does not require prior user interaction beyond browsing the page. The combination of high severity, low exploitation probability, and broad platform coverage places the overall risk at a moderate to high level for organizations that rely on Chrome for web access.

Generated by OpenCVE AI on April 2, 2026 at 04:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Google Chrome update (version 146.0.7680.178 or newer) on all affected devices.
  • Verify the update by checking the browser version or using the update status page.
  • If a patch cannot be applied immediately, consider disabling GPU acceleration or restricting access to untrusted web content until the update becomes available.

Generated by OpenCVE AI on April 2, 2026 at 04:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6192-1 chromium security update
History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Title chromium-browser: Heap buffer overflow in GPU
First Time appeared Apple
Apple macos
Google
Google chrome
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses CWE-120
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Google
Google chrome
Linux
Linux linux Kernel
Microsoft
Microsoft windows
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

threat_severity

Important


Wed, 01 Apr 2026 05:00:00 +0000

Type Values Removed Values Added
Description Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-02T03:56:07.480Z

Reserved: 2026-03-31T20:07:10.100Z

Link: CVE-2026-5272

cve-icon Vulnrichment

Updated: 2026-04-01T13:59:20.761Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-04-01T05:16:00.287

Modified: 2026-04-01T16:36:06.623

Link: CVE-2026-5272

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-31T00:00:00Z

Links: CVE-2026-5272 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T20:18:18Z

Weaknesses