CVE-2026-4444

8.8

Google · Chrome

A stack buffer overflow vulnerability in the WebRTC component of Google Chrome allows remote attackers to trigger stack corruption via a crafted HTML page.

Executive summary

A high severity stack buffer overflow in Google Chrome WebRTC permits remote code execution, posing a critical risk to user device integrity.

Vulnerability

The flaw is a stack buffer overflow (CWE-121) within the WebRTC component of Chrome. An unauthenticated remote attacker can exploit this by enticing a user to navigate to a specifically crafted HTML page, leading to potential stack corruption and arbitrary code execution.

Business impact

Successful exploitation of this vulnerability allows a remote attacker to gain control over the affected browser process, potentially leading to unauthorized data access, malware installation, or system compromise. With a CVSS score of 8.8, this vulnerability represents a significant risk that could lead to full loss of confidentiality, integrity, and availability for the end-user system.

Remediation

Immediate Action: Update Google Chrome to version 146.0.7680.153 or later immediately to resolve the vulnerable WebRTC component.

Proactive Monitoring: Monitor endpoint security logs for unusual browser crashes or unexpected process behavior associated with web browsing activity.

Compensating Controls: Deploy endpoint protection solutions capable of detecting buffer overflow attempts and utilize browser security policies to restrict untrusted scripts where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high severity and the nature of browser-based vulnerabilities, organizations should prioritize the deployment of the Chrome update across all managed endpoints. Failure to patch may expose users to drive-by download attacks, and the urgency of this update is bolstered by the potential for remote code execution.

More Google CVEs

Sources