CVE-2026-2650

8.8

Google · Chrome

A heap buffer overflow vulnerability exists in the Media component of Google Chrome, allowing for potential heap corruption via a crafted HTML page.

Executive summary

A heap buffer overflow vulnerability in Google Chrome poses a significant risk of remote exploitation, potentially leading to total system impact.

Vulnerability

This is a heap buffer overflow (CWE-122) in the Media component. An unauthenticated remote attacker can trigger heap corruption by enticing a user to navigate to a specifically crafted HTML page.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high severity level. Successful exploitation allows for remote code execution or system compromise, which could lead to unauthorized data access, loss of confidentiality, integrity, and availability of the affected workstation.

Remediation

Immediate Action: Update Google Chrome to version 145.0.7632.109 or later immediately to resolve the identified heap corruption flaw.

Proactive Monitoring: Review web proxy and endpoint logs for unusual navigation patterns or attempts to access suspicious external domains that may be hosting malicious HTML content.

Compensating Controls: Ensure that endpoint protection software is active and that browser security settings are configured to block suspicious scripts or untrusted media content.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution and the high CVSS severity, organizations should prioritize patching all instances of Google Chrome across their environment. Standardize the deployment of browser updates to ensure that critical security fixes are applied as soon as they become available from the vendor.

More Google CVEs

Sources