CVE-2026-5291: Medium Inappropriate implementation in WebGL
Chromium: CVE-2026-5291 Inappropriate implementation in WebGL
Other sources
Inappropriate implementation in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-4679
- CVE-2026-4449
- CVE-2026-4674
- CVE-2026-4442
- CVE-2026-4451
- CVE-2026-5292
- CVE-2026-5282
- CVE-2026-3922
- CVE-2026-5280
- CVE-2026-4458
- CVE-2026-3923
- CVE-2026-4462
- CVE-2026-4454
- CVE-2026-4675
- CVE-2025-37752
- CVE-2025-37756
- CVE-2025-37797
- CVE-2025-37890
- CVE-2025-37997
- CVE-2025-38000
- CVE-2025-38001
- CVE-2025-38083
- CVE-2025-38177
- CVE-2025-38350
- CVE-2025-38477
- CVE-2025-38616
- CVE-2025-38617
- CVE-2025-38618
Frequently Asked Questions
What is the severity of CVE-2026-5291?
CVE-2026-5291 has a medium severity rating due to its potential to expose sensitive information.
How do I fix CVE-2026-5291?
To fix CVE-2026-5291, update Google Chrome to version 146.0.7680.178 or later.
What does CVE-2026-5291 affect?
CVE-2026-5291 primarily affects Google Chrome versions prior to 146.0.7680.178.
What type of attack does CVE-2026-5291 facilitate?
CVE-2026-5291 allows a remote attacker to obtain sensitive information from process memory through a crafted HTML page.
Is CVE-2026-5291 present in earlier versions of Chrome?
Yes, CVE-2026-5291 is present in Google Chrome versions earlier than 146.0.7680.178.