CVE-2026-4458

8.8

Google · Chrome

A use after free vulnerability in Google Chrome Extensions allows an attacker to trigger heap corruption via a malicious extension.

Executive summary

Google Chrome versions prior to 146.0.7680.153 are vulnerable to a high severity use after free flaw in the Extensions component that could lead to heap corruption.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Extensions component of Google Chrome. An unauthenticated attacker can trigger this flaw if they successfully convince a user to install a crafted malicious extension.

Business impact

The vulnerability carries a CVSS score of 8.8, indicating a high risk of total system impact including confidentiality, integrity, and availability loss. Successful exploitation could allow for arbitrary code execution or application crashes, potentially leading to unauthorized access to user data or compromise of the host system.

Remediation

Immediate Action: Update Google Chrome to version 146.0.7680.153 or later as specified in the official Google security release.

Proactive Monitoring: Monitor endpoint logs for unusual extension installation activity or unexpected application crashes that may indicate exploitation attempts.

Compensating Controls: Enforce strict organizational policies regarding the installation of browser extensions and use administrative controls to restrict the deployment of non-verified extensions.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

Given the high CVSS score and the potential for heap corruption, this vulnerability poses a significant risk to organizational security. Administrators should prioritize the deployment of the latest Chrome update across all workstations to ensure protection against potential exploitation attempts.

More Google CVEs

Sources