CVE-2026-2315
8.8Google · Chrome
A memory safety vulnerability in Google Chrome WebGPU allows remote attackers to perform out of bounds memory access via a crafted HTML page.
Executive summary
A high severity memory access vulnerability in Google Chrome poses a significant risk of remote code execution or system instability if users navigate to malicious websites.
Vulnerability
The vulnerability is an inappropriate implementation in the WebGPU component, which allows an unauthenticated remote attacker to trigger out of bounds memory access. This flaw requires user interaction, specifically the victim visiting a specially crafted HTML page.
Business impact
The potential for out of bounds memory access often serves as a foundation for remote code execution, which could lead to full system compromise or unauthorized data access. Given the CVSS score of 8.8, this flaw represents a high risk to organizational security, particularly for environments where browser-based workflows are standard. Successful exploitation could result in significant operational disruption and the loss of sensitive data processed within the browser environment.
Remediation
Immediate Action: Update Google Chrome to version 145.0.7632.45 or later to resolve the underlying memory management flaw.
Proactive Monitoring: Review security logs for unusual browser activity or crashes that may indicate attempts to exploit memory vulnerabilities in the WebGPU stack.
Compensating Controls: Implement browser isolation technologies or endpoint protection platforms that can detect and block malicious web-based content before it interacts with the browser rendering engine.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the high severity of this vulnerability and the ubiquity of Google Chrome in corporate environments, administrators must prioritize patching. Ensure that automatic updates are enabled or push the update via centralized management tools immediately to mitigate the risk of remote memory exploitation.