CVE-2026-4446

8.8

Google · Chrome

A use after free vulnerability in the WebRTC component of Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome WebRTC enables remote attackers to achieve heap corruption, posing a significant risk of arbitrary code execution.

Vulnerability

This is a use after free vulnerability (CWE-416) within the WebRTC component. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a specially crafted HTML page, leading to potential heap corruption.

Business impact

Successful exploitation of this memory corruption vulnerability can lead to arbitrary code execution, which grants an attacker the ability to compromise user data, install malicious software, or pivot within the local network. With a CVSS score of 8.8, this flaw represents a high risk to organizational security, particularly for environments where browser-based workflows are central to business operations.

Remediation

Immediate Action: Update all instances of Google Chrome to version 146.0.7680.153 or later immediately to incorporate the provided security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual browser process crashes or unexpected network traffic patterns originating from the browser, which may indicate exploitation attempts.

Compensating Controls: Utilize endpoint detection and response (EDR) solutions to identify and block suspicious browser-based execution chains, and ensure browser security settings are configured to restrict script execution where possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability, combined with the nature of memory corruption in a widely used browser, necessitates immediate patching. Organizations should prioritize deploying the Chrome update across all systems to eliminate the risk of remote exploitation and potential system compromise.

More Google CVEs

Sources