CVE-2026-4677
8.8Google · Chrome
An out of bounds memory read vulnerability in the Google Chrome WebAudio component allows remote attackers to compromise system integrity via a crafted HTML page.
Executive summary
A high-severity out of bounds memory read vulnerability in Google Chrome allows remote attackers to execute arbitrary code or cause system instability via a malicious webpage.
Vulnerability
This vulnerability is an out of bounds read (CWE-125) occurring within the WebAudio implementation of the browser. It allows an unauthenticated remote attacker to trigger memory corruption by enticing a user to visit a specially crafted HTML page.
Business impact
The exploitation of this vulnerability poses a significant risk to organizational endpoints, potentially leading to unauthorized data access, system crashes, or remote code execution. With a CVSS score of 8.8, this flaw represents a high-priority threat that could undermine the confidentiality, integrity, and availability of sensitive browser-based operations.
Remediation
Immediate Action: Update all instances of Google Chrome to version 146.0.7680.165 or later to resolve the underlying memory implementation flaw.
Proactive Monitoring: Monitor endpoint security logs for unusual browser crashes or unexpected process behavior that may indicate an attempt to exploit memory corruption vulnerabilities.
Compensating Controls: Deploy network-level protections and ensure that users are educated on the risks of navigating to untrusted or suspicious websites, which serves as the primary attack vector for this flaw.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available.
Analyst recommendation
Given the prevalence of Chrome in modern enterprise environments and the potential for remote exploitation, this patch should be prioritized within standard maintenance windows. Organizations must ensure that automatic updates are enabled or that deployment scripts are triggered immediately to bring all browser instances to the secure version.