CVE-2026-4460

8.8

Google · Chrome

An out of bounds read vulnerability in the Skia library allows a remote attacker to read memory via a crafted HTML page in Google Chrome.

Executive summary

A high-severity out of bounds read vulnerability in Google Chrome allows remote attackers to access sensitive memory, posing a significant risk of information disclosure and potential system compromise.

Vulnerability

This vulnerability is an out of bounds read (CWE-125) located in the Skia graphics library, which can be triggered by an unauthenticated remote attacker through a maliciously crafted HTML page.

Business impact

The ability for a remote attacker to perform out of bounds memory reads can lead to the exposure of sensitive data processed within the browser environment. With a CVSS score of 8.8, this flaw represents a high risk to organizational security, as it could facilitate further exploitation or the theft of authentication tokens and user information.

Remediation

Immediate Action: Update all Google Chrome installations to version 146.0.7680.153 or later immediately to resolve the vulnerable memory handling.

Proactive Monitoring: Monitor network and endpoint logs for unusual browser activity or crashes that may indicate an attempt to trigger memory-related vulnerabilities.

Compensating Controls: Ensure that enterprise browser policies are configured to restrict the loading of untrusted or suspicious web content where possible, while maintaining standard endpoint protection.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the severity of this vulnerability and its potential for remote exploitation, all administrators must prioritize the deployment of the Chrome security update. Failure to patch may leave systems susceptible to memory-based attacks, which are often precursors to more complex exploitation chains.

More Google CVEs

Sources