CVE-2026-4445

8.8

Google · Chrome

A use after free vulnerability in the WebRTC component of Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome WebRTC enables remote attackers to execute arbitrary code or cause application crashes via malicious web content.

Vulnerability

The vulnerability is a use after free flaw (CWE-416) within the WebRTC component, which can be triggered by an unauthenticated remote attacker using a crafted HTML page to cause heap corruption.

Business impact

Successful exploitation of this flaw could allow a remote attacker to achieve code execution on the user's system, leading to a total compromise of confidentiality, integrity, and availability. Given the CVSS score of 8.8, this vulnerability poses a significant risk to organizational endpoints, as it can be weaponized through common web browsing activities to bypass security controls.

Remediation

Immediate Action: Update all instances of Google Chrome to version 146.0.7680.153 or later immediately to resolve the memory management defect.

Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected process crashes that may indicate exploitation attempts.

Compensating Controls: Ensure that endpoint protection software is active and configured to block known malicious web domains, which may serve as delivery vectors for the crafted HTML pages.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with its potential for remote code execution, makes immediate deployment of the Google Chrome update mandatory. Security administrators should prioritize this update across all corporate workstations to prevent potential exploitation via malicious web navigation.

More Google CVEs

Sources