Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
Google Chrome Sandbox Bypass via Malicious HTML Page
CVE-2026-5273
Summary
A bug in older versions of Google Chrome allowed hackers to potentially take control of a user's browser by sending a specially crafted HTML page. This could happen without the user's knowledge or interaction. Update to the latest version of Google Chrome to fix this issue.
Original title
Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Original description
Use after free in CSS in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Vulnerability type
CWE-416
Use After Free
Published: 1 Apr 2026 · Updated: 1 Apr 2026 · First seen: 1 Apr 2026