LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-5282 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 1, 2026

Google Chrome - Out of Bounds Read

Published: April 1, 2026Updated: April 1, 2026Remote Exploitable

Overview

Google Chrome < 146.0.7680.178 contains an out of bounds read caused by improper memory handling in WebCodecs, letting remote attackers read out of bounds memory via crafted HTML pages.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 3.2%(Probability of exploitation in next 30 days)

Impact

Remote attackers can read out of bounds memory, potentially exposing sensitive information.

Mitigation

Update to version 146.0.7680.178 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 1, 2026

🟠 CVE-2026-5282 - High (8.1) Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-5282/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 1, 2026

🟠 CVE-2026-5282 - High (8.1) Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High) šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-5282/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-5282
Severity
High
CVSS Score
8.1
Type
out_of_bounds_rw
Status
confirmed
EPSS
3.2%
Social Posts
2

CWE

  • CWE-125

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

EPSS Score

3.2%Probability of exploitation in the next 30 days