CVE-2026-4442

8.8

Google · Chrome

A heap buffer overflow vulnerability in the Google Chrome CSS engine allows remote attackers to trigger heap corruption via a specially crafted HTML page.

Executive summary

A high-severity heap buffer overflow in Google Chrome allows remote attackers to compromise user systems through malicious web content.

Vulnerability

This is a heap buffer overflow (CWE-122) within the CSS processing engine. The vulnerability is triggered when an unauthenticated remote attacker entices a user to visit a malicious webpage.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for total impact on confidentiality, integrity, and availability. Successful exploitation could lead to arbitrary code execution, resulting in full system compromise, data theft, or the installation of malicious software on the end user workstation.

Remediation

Immediate Action: Update all instances of Google Chrome to version 146.0.7680.153 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual process crashes or anomalous behavior originating from the Chrome browser process.

Compensating Controls: Deploy endpoint protection solutions that can detect and block memory corruption exploits and leverage browser-based security policies to restrict the execution of untrusted scripts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution and the high severity score, this vulnerability poses a significant risk to organizational endpoints. Administrators must prioritize the deployment of the latest Chrome security updates across the entire fleet to prevent potential exploitation of this memory corruption flaw.

More Google CVEs

Sources