Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution (CVE-2026-5281 Actively Exploited)
- •Chrome prior to 146.0.7680.177/178 for Windows and Mac
- •Chrome prior to 146.0.7680.177 for Linux
Executive Summary
MS-ISAC Advisory 2026-028 (issued 4/1/2026): multiple vulnerabilities in Google Chrome, the most severe of which could allow for arbitrary code execution via drive-by compromise. Flaws include use-after-free, heap buffer overflow, integer overflow, object corruption, out-of-bounds read, and inappropriate implementation issues across CSS, GPU, Codecs, ANGLE, WebUSB, Web MIDI, V8, WebCodecs, Dawn, WebGL, PDF, WebView, Navigation, and Compositing. Google is aware that an exploit for CVE-2026-5281 exists in the wild.
Municipal Impact
MS-ISAC rates the risk as High for large and medium government entities and Medium for small government entities; municipal agencies should update Chrome immediately given the active exploit.
SMB Impact
MS-ISAC rates the risk as High for large and medium business entities, Medium for small business entities, and Low for home users.
Recommended Actions
- Apply appropriate updates provided by Google to vulnerable systems immediately after appropriate testing.
- Ensure use of only fully supported browsers and email clients.
- Apply the principle of least privilege to all systems and services.
Grey Matter Analysis
References
- https://learn.cisecurity.org/e/799323/cvename-cgi-name-CVE-2026-5281/4vv71c/2665395712/h/xLj_kJnDh43sRk-i0EapwZTB7f9INy_LzPqwX1iGcs0
- https://learn.cisecurity.org/e/799323/nel-update-for-desktop-31-html/4vv6zc/2665395712/h/xLj_kJnDh43sRk-i0EapwZTB7f9INy_LzPqwX1iGcs0
- https://learn.cisecurity.org/e/799323/resources--type-advisory/4vv6yg/2665395712/h/xLj_kJnDh43sRk-i0EapwZTB7f9INy_LzPqwX1iGcs0
Tags
Related Intelligence
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter