CVE-2026-4463

8.8

Google · Chrome

A heap buffer overflow in the WebRTC component of Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page.

Executive summary

A heap buffer overflow vulnerability in Google Chrome WebRTC enables remote attackers to achieve code execution or system crashes via malicious web content.

Vulnerability

This is a heap buffer overflow (CWE-122) within the WebRTC component that can be triggered by an unauthenticated remote attacker through a specially crafted HTML page requiring user interaction.

Business impact

Successful exploitation of this heap buffer overflow can lead to arbitrary code execution or significant application instability. Given the high CVSS score of 8.8, this vulnerability poses a severe risk to organizational endpoints by potentially enabling remote attackers to bypass security boundaries, resulting in unauthorized data access or complete system compromise.

Remediation

Immediate Action: Update Google Chrome to version 146.0.7680.153 or later as specified in the official Google Chrome security release.

Proactive Monitoring: Monitor browser-based traffic for suspicious patterns and review endpoint security logs for unexpected process termination or crashes associated with the Chrome browser.

Compensating Controls: Utilize endpoint protection platforms with browser isolation capabilities or advanced exploit protection features to mitigate the risk of memory corruption attacks.

Exploitation status

Public Exploit Available: exploit_available (false)

Analyst recommendation

Organizations should treat this vulnerability with high priority, given the critical nature of the WebRTC component and the potential for remote code execution. Immediate deployment of the provided vendor update is necessary to secure browser environments against this heap-based attack vector.

More Google CVEs

Sources