CVE-2026-2313

8.8

Google · Chrome

A use after free vulnerability exists in the CSS implementation of Google Chrome, allowing for potential heap corruption.

Executive summary

A high severity use after free vulnerability in Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page.

Vulnerability

This is a use after free flaw (CWE-416) within the CSS component of the browser. The vulnerability can be triggered by an unauthenticated remote attacker who lures a user to a specially crafted HTML page.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for significant impact. Successful exploitation could lead to heap corruption, which typically facilitates arbitrary code execution or browser crashes, potentially compromising user data and machine integrity. Organizations relying on Chrome for business operations face risks of malware delivery or unauthorized system access if endpoints are not secured.

Remediation

Immediate Action: Update all Google Chrome instances to version 145.0.7632.45 or later immediately.

Proactive Monitoring: Review endpoint security logs for unusual browser crashes or unexpected memory errors associated with the Chrome process.

Compensating Controls: Deploy endpoint protection platforms capable of identifying and blocking malicious web content or exploit attempts targeted at browser memory management.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the severity of this vulnerability and the potential for remote exploitation, administrators must prioritize the deployment of the latest Chrome security updates. Ensure that automatic update mechanisms are enabled and verified across all corporate assets to mitigate the risk of heap corruption attacks.

More Google CVEs

Sources