CVE-2026-4674
8.8Google · Chrome
A high-severity out of bounds memory read vulnerability in Google Chrome allows remote attackers to access unauthorized memory via crafted HTML pages.
Executive summary
Google Chrome versions prior to 146.0.7680.165 contain an out of bounds read vulnerability in CSS that could lead to unauthorized memory access.
Vulnerability
This vulnerability is an out of bounds read flaw (CWE-125) triggered when processing CSS. The vulnerability is exploitable by an unauthenticated remote attacker through a specially crafted HTML page.
Business impact
The ability for a remote attacker to perform out of bounds memory access poses a significant threat to data confidentiality and system integrity. With a CVSS score of 8.8, this high-severity flaw could potentially lead to information disclosure or facilitate further exploitation chains, placing sensitive user data and browser sessions at risk.
Remediation
Immediate Action: Update Google Chrome to version 146.0.7680.165 or later to resolve the underlying memory access issue.
Proactive Monitoring: Security teams should monitor endpoint logs for browser crashes or unusual memory patterns that may indicate attempts to trigger memory corruption vulnerabilities.
Compensating Controls: Ensure that browser security settings are strictly enforced via Group Policy or MDM solutions, and encourage users to utilize updated software to minimize the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this memory corruption vulnerability and its potential for remote exploitation, all organizations should prioritize the deployment of the latest Google Chrome updates. Immediate patching is the most effective method to neutralize this risk and ensure continued browser security.