CVE-2026-1861Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 18 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 13 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 7 mentions (2026-02-04); latest day: 1
  • 18 total mentions across 7 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline18 mentions / 7d
02457Mentions · 2026-02-03: 2Mentions · 2026-02-04: 7Mentions · 2026-02-05: 3Mentions · 2026-02-06: 2Mentions · 2026-02-08: 1Mentions · 2026-02-09: 2Mentions · 2026-02-12: 1Patch / Workaround · 2026-02-04: 5Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-09: 2Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 5Technical Details · 2026-02-05: 2Technical Details · 2026-02-06: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-12: 102-0302-0402-0502-0602-0802-0902-12
Signal classification3 categories
Patch
1161.1%
Disclosure
422.2%
General
316.7%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-032
Disclosure2
2026-02-047
Disclosure1General1Patch5
2026-02-053
General1Patch2
2026-02-062
General1Patch1
2026-02-081
Patch1
2026-02-092
Patch2
2026-02-121
Disclosure1
Full discourse18 posts
  • @Welsh ICP Conviction@ICPLEGEND1966
    Patch

    Another @googlechrome Security Alert — Meanwhile $ICP ♾️ by @dfinity Runs Verifiable Apps On-Chain Without Trusting the Browser. Facts Google disclosed two high-severity Chrome vulnerabilities (Feb 2026): CVE-2026-1861: Heap buffer overflow in libvpx video codec. CVE-2026-1862: Type confusion in the V8 JavaScript engine. Patches are released gradually. Fix only activates after the user restarts the browser. Chrome has ~3 billion users, making it the largest consumer attack surface. Structural reality of Web2 This is not an isolated event. It is how the current web works: Code executes on user devices. Security depends on: Patch cycles User restarts Trusted backends Invisible server updates. A single browser flaw can expose billions of endpoints. How $ICP by @dfinity is different $ICP changes the execution model of the web. On ICP: Applications run on-chain, not on local servers. Code is: Deterministic Verifiable Tamper-resistant Frontend and backend logic can both live on-chain. Users receive cryptographically certified responses. Result: No hidden server logic. No silent backend changes. Reduced trust in opaque infrastructure. Security model comparison Traditional Web2 Local browser execution Centralized servers Frequent critical CVEs Trust-based compute User-dependent patching $ICP On-chain compute, Verifiable execution Single canonical app state, Cryptographic response certification, Reduced trust assumptions. Bottom line Browser security alerts will keep happening. That is inherent to the client-side Web2 model. ICP represents a different architecture: Verifiable compute On-chain applications Reduced reliance on trust and patch cycles Security patches treat symptoms. Verifiable on-chain compute changes the system. $ICP ♾️ by @dfinity

    Post summary

    Google disclosed two high‑severity Chrome vulnerabilities (CVE‑2026‑1861 and CVE‑2026‑1862) and is rolling out patches gradually, with fixes applying after a browser restart; no active exploitation is reported.

    130250722
    1.2K followersView on X
  • عالم التكنولوجيا@Q8Pro
    General

    @Darksweet1984 ثغرة الأخطر CVE-2026-1862 الثغرة المسؤولة عن تشفير CVE-2026-1861

    Post summary

    The tweet merely references two CVEs without providing any exploitation, patch, or technical details.

    010352.6K
    629.8K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1861 Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom… https://www.cve.org/CVERecord?id=CVE-2026-1861

    Post summary

    The text provides a basic disclosure of CVE-2026-1861, detailing a heap buffer overflow in libvpx within Google Chrome, but offers no PoC, exploit code, active exploitation evidence, or patch information.

    01020303
    56.5K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Google Chrome の脆弱性 CVE-2026-1861/1862 が FIX:任意コード実行とシステム・クラッシュの恐れ https://iototsecnews.jp/2026/02/04/chrome-vulnerabilities-let-attackers-execute-arbitrary-code-and-crash-system/ この問題の原因は、Google Chrome のメモリ処理における不備にあります。具体的には、JavaScript エンジンである V8 において、データ・タイプを正しく識別せずに誤ったメモリ領域を操作してしまうタイプ・コンフュージョンの脆弱性と、動画処理ライブラリである libvpx において、用意されたメモリ枠を越えてデータを書き込んでしまうヒープバッファ・オーバーフローの脆弱性という、2 つの不具合が発生しています。これらの不備がある状態で悪意のあるWebサイトを閲覧すると、ブラウザが処理を誤り、最悪の場合にはコンピュータ内での外部プログラムの実行や、ブラウザの強制終了に至る恐れがあります。ご利用のチームは、ご注意ください。 #Chrome #CVE20261861 #CVE20261862 #Google #Vulnerability

    Post summary

    The post reports that CVE‑2026‑1861/1862 in Chrome involve type‑confusion and heap overflow, allowing arbitrary code execution and system crashes, but provides no PoC, exploit, or patch details.

    02000218
    483 followersView on X
  • VulnTracker@vuln_tracker
    Patch

    🚨 New #Chrome security updates patch critical vulnerabilities that could let attackers execute arbitrary code or crash systems — including heap buffer overflow and type confusion flaws. Stay on top of threats like CVE-2026-1862 & CVE-2026-1861 and hundreds more with VulnTracker! 👉For full details about these CVEs, check out: https://vulntracker.io/dashboard?date_type=updated #cybersecurity #infosec #vulnerability #vulnerabilitytracking #Chrome #zeroday #vulnerabilityintelligence

    Post summary

    The tweet announces Chrome security updates that patch critical vulnerabilities, specifically mentioning heap buffer overflow and type confusion flaws.

    00020197
    333 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en Google Chrome ❗ CVE-2026-1862 ❗ CVE-2026-1861 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-google-chrome-13/ https://t.co/McEcGcqJKG

    Post summary

    The post lists two CVE identifiers related to Google Chrome and directs readers to external links for more information.

    01000158
    6.6K followersView on X
  • 【學】@manabu2111
    Patch

    「Microsoft Edge」にセキュリティ更新 ~デスクトップ版に加え、Android版にも - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2083975.html 、スクリプトエンジン「V8」がv14.4.24.9へと更新されており、以下の脆弱性が解消されているようだ、 CVE-2026-1861、Heap buffer overflow in libvpx、 (続く)

    Post summary

    Microsoft Edge’s Android update includes a patch for CVE‑2026‑1861, a heap buffer overflow in libvpx; no PoC, exploit, or active exploitation is mentioned.

    1000083
    2.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Google Patches High-Severity Chrome Flaws (CVE-2026-1861, CVE-2026-1862) That Could Enable RCE or Crashes Google shipped a Chrome Stable update (144.0.7559.132/.133) fixing two high-severity memory-corruption issues—heap buffer overflow in libvpx (CVE-2026-1861) and type confusion in V8 (CVE-2026-1862)—that could be triggered by malicious web content to crash the browser or potentially enable code execution. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.techrepublic.com/article/news-google-chrome-security-update-february-2026/

    Post summary

    Google released a stable Chrome update addressing two high‑severity memory‑corruption CVEs that could lead to RCE or crashes; no active exploitation or PoC reported.

    0000174
    191 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-1861 2 - CVE-2004-0200 3 - CVE-2026-20026 4 - CVE-2025-46298 5 - CVE-2025-68121 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists five trending CVEs without providing any additional technical details or actionable information.

    00010191
    1.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 144 emergency update patches two “High” bugs enabling code execution and browser crashes Google pushed Chrome 144.0.7559.132/.133 to fix CVE-2026-1862 (V8 type confusion) and CVE-2026-1861 (libvpx heap buffer overflow), where a user visiting a crafted site/video can trigger memory corruption that may lead to renderer-level arbitrary code execution or DoS—update now as details remain restricted until most users patch. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/chrome-vulnerabilities-arbitrary-code-2/

    Post summary

    Google issued an emergency patch for Chrome 144 to address two high‑severity bugs (CVE‑2026‑1862 and CVE‑2026‑1861) that could enable code execution or denial of service via crafted sites/videos; users are urged to update promptly.

    0001070
    192 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1861 - High Heap buffer overflow in libvpx in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: H... https://www.thehackerwire.com/vulnerability/CVE-2026-1861/ https://t.co/qJ3NXp2KYi

    Post summary

    A high‑severity heap buffer overflow in Chrome’s libvpx (before 144.0.7559.132) permits potential remote exploitation via crafted HTML, with no PoC, exploit, patch, or active exploitation reported.

    0000186
    113 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    📢 Critical Update Alert for #openSUSE Users! 📢 Swipe left for crucial steps to secure your system. A severe flaw in Chromium (CVE-2026-1861) requires an immediate patch. Read more:👉 https://tinyurl.com/3yk7kk9n #Security https://t.co/6nYidr1sEP

    Post summary

    The tweet alerts openSUSE users to a severe Chromium vulnerability (CVE‑2026‑1861) and urges them to apply the immediate patch; no exploit code or active exploitation is referenced.

    0000074
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    URGENT: #Fedora 43 Chromium update patches critical RCE flaws: heap overflow in libvpx (CVE-2026-1861) and type confusion in V8 (CVE-2026-1862). Exploitable via crafted HTML. Read more: 👉 https://tinyurl.com/5j2hba73 #Security https://t.co/7kKAy8K0Hb

    Post summary

    The Fedora 43 Chromium update addresses two critical RCE flaws—heap overflow in libvpx and type confusion in V8—both exploitable via crafted HTML.

    0000076
    1.3K followersView on X
  • Brumaire William Boamson@williamboamson
    Patch

    Google corrige 2 failles critiques dans Chrome (CVE-2026-1862, CVE-2026-1861) permettant exécution de code arbitraire ou crash via sites malveillants. Mettez à jour vers Chrome 144.0.7559.132 + dès maintenant. #chevalyeTek https://t.co/ua9Sb9oRCp

    Post summary

    Google released patches for CVE‑2026‑1862 and CVE‑2026‑1861, which allow arbitrary code execution or crashes via malicious sites; users should upgrade to Chrome 144.0.7559.132 or newer.

    0000065
    90 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A heap buffer overflow (CVE-2026-1861) in Chromium's libvpx could lead to heap corruption via crafted HTML. Keep browsers updated. #Chromium #Security #CVE https://www.pulsepatch.io/posts/cve-2026-1861-chromium-libvpx-heap-buffer-overflow

    Post summary

    The article reports a heap buffer overflow in Chromium's libvpx (CVE-2026-1861) that can cause heap corruption via crafted HTML, and urges users to keep browsers updated to mitigate the risk.

    0000087
    1 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 144 emergency update fixes two high-severity memory bugs enabling crashes and potential code execution Google released Chrome 144.0.7559.132/.133 to patch CVE-2026-1861 (libvpx heap buffer overflow) and CVE-2026-1862 (V8 type confusion), both memory-corruption flaws that can be triggered via crafted web content and could be weaponized for arbitrary code execution or browser instability. Update immediately as full technical details remain restricted until most users are patched. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/chrome-vulnerabilities/

    Post summary

    Google released an emergency Chrome 144 update to patch two high‑severity memory‑corruption bugs (CVE‑2026‑1861 and CVE‑2026‑1862). The update is available, but full technical details remain restricted until most users are patched.

    0000071
    192 followersView on X
  • 【學】@manabu2111
    Patch

    「Google Chrome」に2件の脆弱性、「libvpx」「V8」の欠陥を修正 - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2083222.html 、本リリースでは、以下の2件の脆弱性が修正、 CVE-2026-1861、Heap buffer overflow in libvpx、 CVE-2026-1862、Type Confusion in V8、 深刻度の評価は、いずれも4段階中上から2番目の「High」

    Post summary

    The article reports that Google Chrome has fixed two high‑severity vulnerabilities—CVE‑2026‑1861 (heap buffer overflow in libvpx) and CVE‑2026‑1862 (type‑confusion in V8).

    0000051
    2.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Google Chrome (CVE-2026-1861) https://vuldb.com/?id.344165

    Post summary

    The message announces the addition of CVE-2026-1861, a vulnerability in Google Chrome, linking to a VulDB entry without providing further technical or exploit details.

    0000067
    2.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more