CVE-2026-4439Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-20); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-21: 2Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-21: 2Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 203-2003-2103-26
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-212
Patch2
2026-03-261
Patch1
Full discourse5 posts
  • pablito.eth 🦇🔊 @ EthCC 🇫🇷@PabloSabbatella
    Patch

    🚨 CHROME SECURITY UPDATE 🚨: Everyone should force Google Chrome update now. It fixes 26 vulnerabilities, 3 of them being critical: - CVE-2026-4439 > WebGL - Out of bounds memory access - CVE-2026-4440 > WebGL > Out of bounds read and write - CVE-2026-4441 > Base - Use after free 👉 How to: Top right > 3 dots > Settings > About Chrome > Update and relaunch.

    Post summary

    Google Chrome urges users to update to address three critical CVEs involving WebGL out‑of‑bounds access and a use‑after‑free, providing clear instructions to apply the patch.

    2301912.2K
    82.8K followersView on X
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-4439)[475877320][Imagination][command buffer]OOB access(IMG compiler has issues when uniform block count limits limits are exceeded) https://chromium-review.googlesource.com/c/chromium/src/+/7568129 Reported by Goodluck

    Post summary

    CVE-2026-4439 is disclosed as an out‑of‑bounds access bug in Imagination's IMG compiler triggered by exceeding uniform block count limits, with technical details provided but no exploit, patch, or proof of concept referenced.

    000621.2K
    4.9K followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 146.0.7680.153/154 (Windows および Mac) および 146.0.7680.153 (Linux) をリリース. CVE ベースで Critical 3 件 ・CVE-2026-4439 ・CVE-2026-4440 ・CVE-2026-4441 High 22 件の全 26 件の脆弱性に対処. https://x.com/kawn2020/status/2037071642309067082

    Post summary

    Google announced the release of Chrome 146.0.7680.153/154, patching 26 vulnerabilities—including three critical CVEs—without providing any proof‑of‑concept, exploit details, or active exploitation evidence.

    1000064
    87 followersView on X
  • Techgines@nxtgen579255
    Patch

    Chrome 146.0.7680.153/154 is out with 26 security fixes, including 3 Critical bugs: CVE-2026-4439 & 4440 (WebGL) + CVE-2026-4441 (Base). If your update is pending, don’t wait—relaunch Chrome now. https://www.techgines.com/post/chrome-146-security-update-146-0-7680-153-154-the-big-three-critical-rce-bugs-explained #Chrome146 #CyberSecurity #InfoSec #CVE #RCE https://t.co/7zy5xJET0r

    Post summary

    The tweet promotes the Chrome 146 update, highlighting three critical RCE fixes, and urges users to apply the patch.

    0000091
    4 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4439 Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted… https://www.cve.org/CVERecord?id=CVE-2026-4439

    Post summary

    A new CVE-2026-4439 details an out‑of‑bounds memory access issue in Chrome WebGL on Android capable of sandbox escape, but no exploit, patch, or active exploitation is reported.

    00000126
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more