CVE-2026-4675

8.8

Google · Chrome

A heap buffer overflow in the WebGL component of Google Chrome allows remote attackers to perform out of bounds memory reads via a crafted HTML page.

Executive summary

A heap buffer overflow vulnerability in Google Chrome WebGL could allow a remote attacker to execute unauthorized memory operations, posing a high security risk to end users.

Vulnerability

This is a heap buffer overflow (CWE-122) within the WebGL implementation. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page.

Business impact

Successful exploitation of this vulnerability can lead to unauthorized memory access, potentially resulting in system crashes or information disclosure. With a CVSS score of 8.8, this flaw represents a significant risk to organizational endpoints, as it facilitates remote exploitation against common web browsing activities.

Remediation

Immediate Action: Update Google Chrome to version 146.0.7680.165 or later immediately to resolve the vulnerable memory handling.

Proactive Monitoring: Monitor endpoint browser versions via centralized management consoles to ensure all instances are updated to the patched release.

Compensating Controls: While browser-level patches are the primary control, ensure that endpoint protection platforms are active to detect and block malicious web-based content.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity of this vulnerability and its potential for remote exploitation through standard web browsing, organizations must prioritize the deployment of the Google Chrome update. Verify that automatic updates are enabled or push the update through enterprise deployment tools to ensure all managed devices are protected against this memory corruption flaw.

More Google CVEs

Sources