CVE-2026-2314Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in Codecs in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-12); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-02-11: 3Mentions · 2026-02-12: 4Mentions · 2026-02-13: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-12: 3Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 1Technical Details · 2026-02-20: 102-1102-1202-1302-20
Signal classification2 categories
Patch
666.7%
Disclosure
333.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-113
Disclosure2Patch1
2026-02-124
Disclosure1Patch3
2026-02-131
Patch1
2026-02-201
Patch1
Full discourse9 posts
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chrome 145のデスクトップ向け安定版で3件の重大な脆弱性を修正(CVE-2026-2313,CVE-2026-2314,CVE-2026-2315) https://rocket-boys.co.jp/security-measures-lab/google-chrome-145-desktop-fixes-three-critical-vulnerabilities-cve-2026-2313-cve-2026-2314-cve-2026-2315/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Google Chrome 145 has been patched to fix three critical vulnerabilities (CVE‑2026‑2313, CVE‑2026‑2314, CVE‑2026‑2315), and the update is available.

    00011138
    318 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-2314: HIGH] Critical heap buffer overflow in pre-145.0.7632.45 Google Chrome Codecs enabled remote attackers to corrupt heap via crafted HTML page. Patch to 145.0.7632.45 recommended.#cve,CVE-2026-2314,#cybersecurity https://cvefind.com/CVE-2026-2314

    Post summary

    A critical heap buffer overflow in Google Chrome is disclosed; a patch to version 145.0.7632.45 is recommended to mitigate the vulnerability.

    0001061
    583 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ Critical Fedora 43 Update! 🛡️ Is your system exposed? A new Chromium update (145.0.7632.75) patches 13 security flaws, including a critical heap overflow (CVE-2026-2314) that could lead to remote code execution. Read more: 👉 https://tinyurl.com/5e7v52wv #Security https://t.co/lJQNU1Lo9F

    Post summary

    The tweet warns that a new Chromium update (145.0.7632.75) patches CVE-2026-2314, a critical heap overflow capable of remote code execution.

    0000047
    1.3K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 ships security update fixing 11 bugs, including 3 high-severity flaws Chrome 145 (145.0.7632.45/46) patches 11 vulnerabilities, including three high-severity issues: a CSS use-after-free (CVE-2026-2313), a heap buffer overflow in Codecs (CVE-2026-2314), and a WebGPU inappropriate implementation bug (CVE-2026-2315); Google says none are known to be exploited in the wild. Organizations should still push the update quickly given browser-bug exploitability and user exposure at scale. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/chrome-145-patches-11-vulnerabilities/

    Post summary

    Chrome 145 releases an update that patches three high‑severity vulnerabilities—use‑after‑free, heap overflow, and a WebGPU bug—none of which are reported as exploited in the wild; users are urged to apply the patch promptly.

    0000040
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 Security Update Patches 11 Bugs, Including High-Severity Code-Execution Flaws Google shipped Chrome 145 for Windows/macOS/Linux fixing 11 vulnerabilities, led by CVE-2026-2313 (high, use-after-free in CSS) plus CVE-2026-2314 (high, heap overflow in Codecs) and CVE-2026-2315 (high, WebGPU), all with potential code-execution impact. Users should update to 145.0.7632.45 (Linux) or 145.0.7632.45/46 (Windows/Mac) as the rollout progresses. 🎯 Target: Global / Chrome Users (Windows, macOS, Linux) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/chrome-security-update-patch-vulnerabilities/

    Post summary

    Google released Chrome 145 with patches for 11 CVEs, including high‑severity code‑execution bugs, and urged users to upgrade to the new version.

    00000108
    191 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A heap buffer overflow (DEBIAN-CVE-2026-2314) affects `Chromium` and `Google Chrome` prior to 145.0.7632.45. Exploitation via crafted HTML is possible. Monitor for official updates. #Chromium #CVE #infosec https://www.pulsepatch.io/posts/chromium-heap-buffer-overflow-debian-cve-2026-2314

    Post summary

    A heap buffer overflow exists in Chromium and Google Chrome before version 145.0.7632.45, exploitable via crafted HTML; users are advised to watch for official updates.

    0000045
    1 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 Emergency Update Fixes 11 High-Severity Browser Bugs Linked to Code Execution Risk Google shipped Chrome 145.0.7632.45 (announced Feb 10) patching 11 security flaws—including high-severity use-after-free and heap buffer overflow issues (e.g., CVE-2026-2313 in CSS, CVE-2026-2314 in Codecs, CVE-2026-2315 in WebGPU)—that could enable remote code execution or memory corruption via malicious content. This matters because browser RCE is a top initial-access path, so fast patch adoption reduces drive-by and phishing-delivered exploit success. 🎯 Target: Global / Chrome Users (Windows, macOS, Linux) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/chrome-security-update-patches-vulnerabilities-2/

    Post summary

    Google released an emergency update to Chrome 145.0.7632.45 that fixes 11 high‑severity bugs, including CVE‑2026‑2313/2314/2315, which could enable remote code execution; all Chrome users are advised to install the patch.

    0000036
    191 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2314 Heap Buffer Overflow in Google Chrome Codecs Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2314

    Post summary

    The text announces a heap buffer overflow vulnerability (CVE‑2026‑2314) in Google Chrome codecs that permits remote code execution, without reporting PoC, exploitation, or patch information.

    0000053
    4.0K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Google Chrome (CVE-2026-2314) https://vuldb.com/?id.345565

    Post summary

    The text announces the addition of CVE‑2026‑2314, an important vulnerability affecting Google Chrome, and provides a link to a vulnerability database page.

    0000084
    2.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more