CVE-2026-4440Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Out of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Critical)

3.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-20); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-21: 1Mentions · 2026-03-26: 1Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-03-21: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 1Technical Details · 2026-03-26: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 103-2003-2103-2604-1304-14
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-211
Patch1
2026-03-261
Patch1
2026-04-131
Disclosure1
2026-04-141
Disclosure1
Full discourse6 posts
  • Germán Fernández@1ZRR4H
    Disclosure

    📌 CVE-2026-4440: Google Chrome WebGL Out-of-Bounds Read/Write Vulnerability Allows Remote Code Execution. 🤔 #opendir http://100.48.195[.]190/

    Post summary

    The text announces CVE‑2026‑4440, detailing a WebGL out‑of‑bounds read/write flaw in Google Chrome that enables remote code execution, and provides a link that may lead to further information or a PoC.

    427117011520.8K
    38.1K followersView on X
  • pablito.eth 🦇🔊 @ EthCC 🇫🇷@PabloSabbatella
    Patch

    🚨 CHROME SECURITY UPDATE 🚨: Everyone should force Google Chrome update now. It fixes 26 vulnerabilities, 3 of them being critical: - CVE-2026-4439 > WebGL - Out of bounds memory access - CVE-2026-4440 > WebGL > Out of bounds read and write - CVE-2026-4441 > Base - Use after free 👉 How to: Top right > 3 dots > Settings > About Chrome > Update and relaunch.

    Post summary

    The post alerts users of a Chrome update that patches 26 vulnerabilities, including 3 critical ones, and instructs how to perform the update.

    2301912.2K
    82.8K followersView on X
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-4440)[485935305][WebGL]OOBRW https://chromium-review.googlesource.com/c/chromium/src/+/7630664 Reported by c6eed09fc8b174b0f3eebedcceb1e792

    Post summary

    The message announces CVE‑2026‑4440 for Chromium, indicating an out‑of‑bounds read/write flaw and links to a code review, but provides no PoC, exploit, or patch details.

    0001261.9K
    4.9K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @1ZRR4H Notable find, @1ZRR4H. 🚨 CVE-2026-4440 highlights a critical WebGL out-of-bounds read/write flaw in Google Chrome that could lead to RCE. With PoCs already circulating, timely patching and browser updates are essential. Track it on Vulntracker: https://vulntracker.io

    Post summary

    The post announces CVE-2026-4440, a critical WebGL out-of-bounds flaw in Chrome that allows RCE, notes existing PoCs, and urges users to apply patches promptly.

    00001666
    538 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 146.0.7680.153/154 (Windows および Mac) および 146.0.7680.153 (Linux) をリリース. CVE ベースで Critical 3 件 ・CVE-2026-4439 ・CVE-2026-4440 ・CVE-2026-4441 High 22 件の全 26 件の脆弱性に対処. https://x.com/kawn2020/status/2037071642309067082

    Post summary

    Google released Chrome 146.0.7680.153/154 with patches for 26 vulnerabilities, including 3 critical CVEs (2026‑4439, 4440, 4441).

    1000064
    87 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4440 Out of bounds read and write in WebGL in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chrom… https://www.cve.org/CVERecord?id=CVE-2026-4440

    Post summary

    The text announces CVE-2026-4440 as an out-of-bounds memory access in Chrome's WebGL, allowing arbitrary read/write through a crafted HTML page, without reference to PoC, exploitation, or mitigation.

    00000112
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more