


Perceptive Security
SOC/SIEM Consultancy

Use after free in Compositing in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to potentially perform…
Published:
31 March 2026 at 22:00:00
Alert date:
1 April 2026 at 17:02:06
Source:
nvd.nist.gov
Web Technologies
A use after free vulnerability in Google Chrome's Compositing component prior to version 146.0.7680.178 allows remote attackers who have compromised the renderer process to potentially perform sandbox escape attacks via crafted HTML pages. The vulnerability is rated as high severity by Chromium security team and enables privilege escalation from renderer process compromise to full sandbox escape.
Technical details
Mitigation steps:
Affected products:
Google Chrome
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-5290
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_31.html
https://issues.chromium.org/issues/496205576
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
