
CVE-2026-5278 Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium se… https://www.cve.org/CVERecord?id=CVE-2026-5278
Post summary
The entry discloses CVE-2026-5278 as a use‑after‑free bug in Chrome's Web MIDI on Android that permits remote code execution through a crafted HTML page; no PoC, exploit code, active exploitation evidence, or patch details are provided.

