CVE-2026-2650Patch(google / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-19); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-18: 1Mentions · 2026-02-19: 3Mentions · 2026-02-20: 1Mentions · 2026-02-24: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 1Technical Details · 2026-02-24: 102-1802-1902-2002-24
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-181
Disclosure1
2026-02-193
Disclosure1General1Patch1
2026-02-201
Patch1
2026-02-241
Patch1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2650 Heap Buffer Overflow in Google Chrome Media Rendering Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2650

    Post summary

    CVE-2026-2650 is a heap buffer overflow in Google Chrome's media rendering module that can lead to remote code execution.

    0001175
    4.0K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Google Pushes Emergency Chrome Patch for High-Severity PDFium & V8 Flaws (CVE-2026-2648/2649) Google released an emergency Chrome Stable update (145.0.7632.109/110 for Windows/macOS; 144.0.7559.109 for Linux) fixing two high-severity memory issues—PDFium heap buffer overflow (CVE-2026-2648) and a V8 integer overflow (CVE-2026-2649)—plus a Media heap overflow (CVE-2026-2650). This matters because these core-engine bugs can enable crashes or arbitrary code execution via malicious content, so rapid patching reduces browser RCE risk across enterprises. 🎯 Target: Global #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/google-chrome-emergency-security-update/

    Post summary

    Google released an emergency patch for Chrome to fix high‑severity PDFium and V8 memory issues, emphasizing the need for rapid deployment to mitigate potential RCE risks.

    00001108
    196 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `Chromium` is affected by DEBIAN-CVE-2026-2650, a heap buffer overflow in `Media`. A crafted HTML page can lead to heap corruption. Apply available `Chromium` security updates. #Chromium #Infosec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-2650-chromium-heap-buffer-overflow

    Post summary

    Chromium is vulnerable to DEBIAN-CVE-2026-2650, a heap buffer overflow triggered by crafted HTML pages; users should apply the available Chromium security updates to mitigate the risk.

    0000034
    1 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Google Chrome (CVE-2026-2650) https://vuldb.com/?id.346669

    Post summary

    The text reports an increased severity for CVE-2026-2650 in Google Chrome but offers no further technical details, exploit evidence, or mitigation steps.

    0000057
    2.1K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity alert: Heap buffer overflow in Google Chrome (pre-145.0.7632.109) may enable remote code execution via malicious HTML. Update now to stay secure! 🔒 https://radar.offseq.com/threat/cve-2026-2650-heap-buffer-overflow-in-google-chrom-0bc72c99 #OffSeq #Chrome #Vuln... https://t.co/Cgl4tRLPjV

    Post summary

    The tweet alerts to a high‑severity heap buffer overflow (CVE‑2026‑2650) in Google Chrome that could enable remote code execution via malicious HTML, and urges users to apply the available update.

    0000050
    265 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2650 Heap buffer overflow in Media in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… https://www.cve.org/CVERecord?id=CVE-2026-2650

    Post summary

    A heap buffer overflow vulnerability (CVE-2026-2650) in Google Chrome before version 145.0.7632.109 may allow a remote attacker to corrupt heap memory via a crafted HTML page.

    00000153
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more