CVE-2026-4673

8.8

Google · Chrome

A heap buffer overflow in the WebAudio component of Google Chrome allows a remote attacker to perform an out of bounds memory write via a crafted HTML page.

Executive summary

A heap buffer overflow vulnerability in Google Chrome allows remote attackers to execute arbitrary code or cause system crashes through malicious web content.

Vulnerability

This is a heap buffer overflow (CWE-122) in the WebAudio engine. It is an unauthenticated, remote vulnerability that requires user interaction to trigger by enticing a victim to visit a crafted HTML page.

Business impact

The ability for a remote attacker to achieve an out of bounds memory write poses a severe risk to data integrity and system stability. With a CVSS score of 8.8, this vulnerability is classified as High severity, as successful exploitation could lead to full system compromise or arbitrary code execution within the browser context, potentially exposing sensitive user data or internal network resources.

Remediation

Immediate Action: Update Google Chrome to version 146.0.7680.165 or later immediately to incorporate the vendor security patches.

Proactive Monitoring: Monitor endpoint security logs for unusual browser crashes or unexpected memory spikes that may indicate exploitation attempts.

Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious web-based content or known exploit patterns associated with memory corruption.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the prevalence of Google Chrome in enterprise environments, this vulnerability represents a significant risk. Administrators should prioritize the deployment of the latest Chrome stable channel update across all managed workstations to prevent potential remote code execution attacks.

More Google CVEs

Sources