CVE-2026-2314

8.8

Google · Chrome

A heap buffer overflow vulnerability in Google Chrome's Codecs component allows a remote attacker to trigger heap corruption through a specially crafted HTML page.

Executive summary

A critical heap buffer overflow in Google Chrome allows remote attackers to execute arbitrary code or cause system crashes via malicious HTML content.

Vulnerability

This is a heap buffer overflow (CWE-122) within the Codecs component of the browser. The vulnerability is exploitable by a remote, unauthenticated attacker who lures a user to visit a crafted HTML page, requiring user interaction to trigger the corruption.

Business impact

The exploitation of this flaw can lead to a full compromise of the user's browser environment, potentially resulting in the loss of sensitive data, unauthorized access to local resources, or complete system instability. Given the high CVSS score of 8.8, this vulnerability represents a significant risk to organizational endpoints, as web browsers remain a primary target for initial access and malware delivery.

Remediation

Immediate Action: Update all installations of Google Chrome to version 145.0.7632.45 or later immediately.

Proactive Monitoring: Review endpoint security logs for unusual browser crashes or unexpected process behavior associated with the Chrome executable.

Compensating Controls: Utilize browser-based security policies or endpoint protection platforms to restrict the execution of untrusted scripts and monitor for suspicious network activity originating from browser processes.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this heap buffer overflow necessitates an urgent patching cycle across all managed assets. Administrators should prioritize the deployment of the Google Chrome update to version 145.0.7632.45 or higher to eliminate the risk of remote heap corruption and potential code execution.

More Google CVEs

Sources