
Google が Chrome 146 を正式リリース:リモート・コード実行などの 29 件の脆弱性を修正 https://iototsecnews.jp/2026/03/12/chrome-security-update-patch-for-29-vulnerabilities-that-allow-remote-code-execution/ 今回の Chrome のアップデートでは、プログラムが確保したメモリ領域に対する扱いの不備が主な原因となっています。特に CVE-2026-3913 では、割り当てられたサイズを超えてデータを書き込んでしまうヒープバッファ・オーバーフローが発生します。また、CVE-2026-3917/CVE-2026-3919 などで指摘された解放済みメモリ使用 (UAF) は、すでに不要として解放されたメモリ領域への不正なアクセスにより発生します。これらのメモリ管理の問題は、悪意の Web ページを閲覧するだけで、リモート・コード実行に至るなどの深刻な影響を招く可能性があるため、注意が必要です。 #Chrome #CVE20263916 #CVE20263917 #CVE20263918 #CVE20263919 #CVE20263921 #CVE20263922 #CVE20263923 #CVE20263924 #Google
Post summary
Google released Chrome 146, addressing 29 vulnerabilities—including CVE‑2026‑3913, CVE‑2026‑3917, and CVE‑2026‑3919—that enable remote code execution via memory‑management flaws such as heap buffer overflows and use‑after‑free. The article focuses on the patch announcement and technical details of the fixes.



