CVE-2026-4445
8.8Google · Chrome
A use after free vulnerability in the WebRTC component of Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page.
Executive summary
A high-severity use after free vulnerability in Google Chrome WebRTC enables remote attackers to execute arbitrary code or cause application crashes via malicious web content.
Vulnerability
The vulnerability is a use after free flaw (CWE-416) within the WebRTC component, which can be triggered by an unauthenticated remote attacker using a crafted HTML page to cause heap corruption.
Business impact
Successful exploitation of this flaw could allow a remote attacker to achieve code execution on the user's system, leading to a total compromise of confidentiality, integrity, and availability. Given the CVSS score of 8.8, this vulnerability poses a significant risk to organizational endpoints, as it can be weaponized through common web browsing activities to bypass security controls.
Remediation
Immediate Action: Update all instances of Google Chrome to version 146.0.7680.153 or later immediately to resolve the memory management defect.
Proactive Monitoring: Monitor endpoint security logs for unusual browser activity or unexpected process crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that endpoint protection software is active and configured to block known malicious web domains, which may serve as delivery vectors for the crafted HTML pages.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability, combined with its potential for remote code execution, makes immediate deployment of the Google Chrome update mandatory. Security administrators should prioritize this update across all corporate workstations to prevent potential exploitation via malicious web navigation.