CVE-2026-4440

8.8

Google · Chrome

A critical out of bounds read and write vulnerability in Google Chrome WebGL allows remote attackers to perform arbitrary memory operations via a crafted HTML page.

Executive summary

Google Chrome versions prior to 146.0.7680.153 contain a critical memory safety vulnerability that allows remote attackers to execute arbitrary read and write operations.

Vulnerability

The vulnerability is an out of bounds read and write error occurring within the WebGL component. This flaw allows an unauthenticated remote attacker to compromise system memory by enticing a user to visit a specially crafted HTML page.

Business impact

The ability to perform arbitrary read and write operations on a user system poses a significant risk to data confidentiality, integrity, and availability. Given the CVSS score of 8.8, this vulnerability is classified as High severity and could facilitate full system compromise or the bypass of browser security sandboxes.

Remediation

Immediate Action: Update all Google Chrome instances to version 146.0.7680.153 or later immediately to incorporate the vendor provided security patches.

Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected behavior associated with WebGL rendering processes.

Compensating Controls: While no direct virtual patch exists for this memory flaw, enforcing strict browser security policies and utilizing endpoint protection software can help mitigate the impact of successful exploitation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this memory safety issue necessitates an immediate organizational update to the latest stable version of Google Chrome. Security teams should prioritize the deployment of this update across all workstations to ensure protection against potential remote code execution attempts leveraging this WebGL flaw.

More Google CVEs

Sources