CVE-2026-3921

8.8

Google · Chrome

A use after free vulnerability in Google Chrome's TextEncoding component allows a remote attacker to trigger heap corruption via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome allows remote attackers to execute arbitrary code or cause heap corruption through malicious web content.

Vulnerability

This is a use after free vulnerability (CWE-416) within the TextEncoding component of Google Chrome. An unauthenticated remote attacker can exploit this flaw by enticing a user to navigate to a specifically crafted HTML page, potentially leading to heap corruption or remote code execution.

Business impact

The exploitation of this vulnerability poses a severe risk to organizational security, as it allows for arbitrary code execution within the context of the browser. With a CVSS score of 8.8, this flaw could lead to the complete compromise of user workstations, unauthorized access to sensitive corporate data, and persistent malware installation. The reliance on user interaction via a crafted webpage does not diminish the risk for environments where employees browse external content.

Remediation

Immediate Action: Update all Google Chrome instances to version 146.0.7680.71 or later immediately.

Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected process behavior associated with the Chrome application.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious web-based exploits, and enforce standard security configurations to limit the impact of browser-based attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability, organizations should prioritize the deployment of the vendor-supplied patch across all managed endpoints. Failure to update may expose users to browser-based attacks that can bypass standard security perimeters. Ensure the update is verified as installed on all systems to mitigate the risk of heap corruption and potential remote code execution.

More Google CVEs

Sources