CVE-2026-4680

8.8

Google · Chrome

A use after free vulnerability in the FedCM component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A high severity use after free vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution via a specially crafted HTML page.

Vulnerability

This is a use after free vulnerability (CWE-416) within the FedCM component of the browser, which can be triggered by an unauthenticated remote attacker through a malicious web page. The attack requires user interaction to visit the crafted site, leading to potential arbitrary code execution within the browser sandbox.

Business impact

Successful exploitation of this vulnerability poses a significant risk to organizational endpoints, as it allows for arbitrary code execution in the context of the user running the browser. With a CVSS score of 8.8, the vulnerability is classified as High, reflecting the potential for full compromise of the browser session and subsequent lateral movement within the local environment.

Remediation

Immediate Action: Update Google Chrome to version 146.0.7680.165 or later immediately to incorporate the security patches provided by the vendor.

Proactive Monitoring: Monitor endpoint logs for suspicious browser activity or crashes associated with the FedCM process, which may indicate attempted exploitation.

Compensating Controls: Ensure that Endpoint Detection and Response (EDR) solutions are active to block or alert on abnormal child processes spawned by the browser.

Exploitation status

Public Exploit Available: False (no confirmed public exploit available).

Analyst recommendation

The severity of this vulnerability necessitates immediate patching across all workstation fleets. Administrators should prioritize the deployment of the Chrome update to mitigate the risk of remote code execution, as the browser remains a primary target for web-based exploitation.

More Google CVEs

Sources