Date Posted: 2026/04/09
[Vulnerability Alert] 21 High-Risk Security Vulnerabilities Found in Chromium-based Browsers, Please Confirm and Patch Immediately
- Subject Explanation: [Vulnerability Alert] 21 High-Risk Security Vulnerabilities Found in Chromium-based Browsers, Please Confirm and Patch Immediately
- Content Description:
- Forwarding National Information Security Analysis and Sharing Center (NISAC) Alert NISAC-200-202604-00000003
- Researchers have discovered 21 high-risk security vulnerabilities (CVE-2026-5272 to CVE-2026-5292) in Chromium-based browsers such as Google Chrome, Microsoft Edge, Vivaldi, Brave, and Opera. Vulnerability types include Buffer Overflow and Use After Free. The most severe vulnerabilities could allow an unauthenticated remote attacker to escape the browser sandbox environment and execute arbitrary code via a specially crafted HTML page. Among them, CVE-2026-5281 has already been exploited by hackers; please confirm and patch immediately.
- Impacted Platforms:
- Google Chrome versions prior to 146.0.7680.177 (exclusive)
- Microsoft Edge versions prior to 146.0.3856.97 (exclusive)
- Vivaldi versions prior to 7.9.3970.47 (exclusive)
- Brave versions prior to 1.88.138 (exclusive)
- Opera versions prior to 129.0.5823.65 (exclusive)
- Suggested Measures:
- Please update Google Chrome to version 146.0.7680.178 and later versions https://support.google.com/chrome/answer/95414?hl=zh-Hant
- Please update Microsoft Edge to version 146.0.3856.97 and later versions https://support.microsoft.com/zh-tw/topic/microsoft-edge-%E6%9B%B4%E6%96%B0%E8%A8%AD%E5%AE%9A-af8aaca2-1b69-4870-94fe-18822dbb7ef1
- Please update Vivaldi to version 7.9.3970.47 and later versions https://help.vivaldi.com/desktop/install-update/update-vivaldi/
- Please update Brave to version 1.88.138 and later versions https://community.brave.com/t/how-to-update-brave/384780
- Please update Opera to version 129.0.5823.65 and later versions https://help.opera.com/en/latest/crashes-and-issues/#updateBrowser
- References:
Computer and Communication Center
Network Systems Division