CVE-2026-3920

8.8

Google · Chrome

A remote attacker can trigger heap corruption via a crafted HTML page due to an out of bounds memory access vulnerability in the WebML component of Google Chrome.

Executive summary

Google Chrome versions prior to 146.0.7680.71 are vulnerable to a high severity memory corruption flaw that could allow a remote attacker to compromise user systems.

Vulnerability

This is an out of bounds memory access vulnerability within the WebML component. It allows an unauthenticated remote attacker to potentially cause heap corruption by enticing a user to visit a specially crafted HTML page.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high risk of exploitation. Successful exploitation could lead to unauthorized code execution within the context of the browser, potentially resulting in full system compromise, data theft, or the installation of malicious software on the host machine.

Remediation

Immediate Action: Update all instances of Google Chrome to version 146.0.7680.71 or later as soon as possible to receive the security fix.

Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected process behavior that may indicate an attempt to trigger memory corruption.

Compensating Controls: Ensure that browser security settings are configured to restrict suspicious site activity and deploy endpoint protection solutions that can detect common exploitation patterns.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution and the severity of the flaw, organizations must prioritize updating Google Chrome across all managed devices. Relying on automated browser updates is recommended, but administrators should verify that the update has successfully applied to all endpoints to mitigate the risk of this high severity vulnerability.

More Google CVEs

Sources