CVE-2026-4679
8.8Google · Chrome
An integer overflow vulnerability in Google Chrome Fonts allows remote attackers to perform an out of bounds memory write via a crafted HTML page.
Executive summary
A critical integer overflow vulnerability in Google Chrome allows unauthenticated remote attackers to execute out of bounds memory operations, creating a significant risk of system compromise.
Vulnerability
This vulnerability is an integer overflow (CWE-472) located within the font rendering engine of Google Chrome. It allows an unauthenticated remote attacker to trigger an out of bounds memory write when a user visits a specially crafted HTML page.
Business impact
The potential impact of this vulnerability is severe, as out of bounds memory write flaws often serve as a gateway for arbitrary code execution or significant application instability. Given the CVSS score of 8.8, this represents a high risk to business operations, potentially leading to unauthorized access to user data or complete system compromise if an attacker successfully exploits the browser environment.
Remediation
Immediate Action: Update Google Chrome to version 146.0.7680.165 or the latest available stable release immediately to patch the font rendering flaw.
Proactive Monitoring: Review security logs for anomalous browser behavior or unexpected crashes that may indicate exploitation attempts involving malformed font objects.
Compensating Controls: Ensure that browser security features such as site isolation are enabled and consider utilizing endpoint protection platforms that can detect memory corruption patterns.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit available in the provided data.
Analyst recommendation
Due to the high severity of this integer overflow vulnerability, organizations should prioritize the deployment of the latest Google Chrome updates across all managed endpoints. Failure to patch allows remote attackers to potentially gain control over the browser session, making rapid remediation essential to maintaining a secure computing environment.