CVE-2026-4461

8.8

Google · Chrome

A heap corruption vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

Google Chrome versions prior to 146.0.7680.153 contain a high-severity heap corruption vulnerability in the V8 engine that could lead to remote code execution.

Vulnerability

This is an inappropriate implementation flaw in the V8 JavaScript engine, which allows an unauthenticated remote attacker to trigger heap corruption by enticing a user to visit a specially crafted HTML page.

Business impact

The ability for a remote attacker to achieve heap corruption through the browser poses a significant threat to organizational data confidentiality and system integrity. With a CVSS score of 8.8, this vulnerability is classified as High, indicating that successful exploitation could result in full system compromise or unauthorized code execution within the context of the user session.

Remediation

Immediate Action: Update all Google Chrome installations to version 146.0.7680.153 or later immediately to incorporate the vendor security patch.

Proactive Monitoring: Review web proxy and browser logs for traffic directed toward suspicious or unknown domains that may be hosting malicious HTML content.

Compensating Controls: Ensure that endpoint protection software is active and configured to detect browser-based exploitation attempts, and consider utilizing browser isolation technologies if immediate patching is not possible across all endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of V8 engine vulnerabilities, organizations must prioritize the deployment of the Google Chrome update across all managed workstations. Failure to apply this patch leaves users exposed to potential drive-by download attacks that could facilitate remote code execution. Immediate transition to the latest stable version is the only effective method to remediate this risk.

More Google CVEs

Sources