CVE-2026-4441Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-20); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-20: 2Mentions · 2026-03-21: 2Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-21: 2Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 203-2003-2103-26
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-212
Patch2
2026-03-261
Patch1
Full discourse5 posts
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-4441)[489381399]UAF in base::OnceCallbackList on re-entrant Notify() https://chromium-review.googlesource.com/c/chromium/src/+/7627506 Reported by Google https://t.co/LWw7h6fyrP

    Post summary

    Google has disclosed CVE-2026-4441, a use‑after‑free vulnerability in Chromium’s base::OnceCallbackList triggered during re‑entrant Notify(), as reported in a Chromium review.

    03019122.5K
    4.9K followersView on X
  • pablito.eth 🦇🔊 @ EthCC 🇫🇷@PabloSabbatella
    Patch

    🚨 CHROME SECURITY UPDATE 🚨: Everyone should force Google Chrome update now. It fixes 26 vulnerabilities, 3 of them being critical: - CVE-2026-4439 > WebGL - Out of bounds memory access - CVE-2026-4440 > WebGL > Out of bounds read and write - CVE-2026-4441 > Base - Use after free 👉 How to: Top right > 3 dots > Settings > About Chrome > Update and relaunch.

    Post summary

    The message urges users to update Google Chrome to fix 26 vulnerabilities, including three critical CVEs in WebGL and a use‑after‑free bug; the update process is detailed for quick remediation.

    2301912.2K
    82.8K followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 146.0.7680.153/154 (Windows および Mac) および 146.0.7680.153 (Linux) をリリース. CVE ベースで Critical 3 件 ・CVE-2026-4439 ・CVE-2026-4440 ・CVE-2026-4441 High 22 件の全 26 件の脆弱性に対処. https://x.com/kawn2020/status/2037071642309067082

    Post summary

    Google released Chrome 146, fixing 26 vulnerabilities, 3 of which are critical CVEs (CVE-2026-4439/4440/4441).

    1000064
    87 followersView on X
  • Techgines@nxtgen579255
    Patch

    Chrome 146.0.7680.153/154 is out with 26 security fixes, including 3 Critical bugs: CVE-2026-4439 & 4440 (WebGL) + CVE-2026-4441 (Base). If your update is pending, don’t wait—relaunch Chrome now. https://www.techgines.com/post/chrome-146-security-update-146-0-7680-153-154-the-big-three-critical-rce-bugs-explained #Chrome146 #CyberSecurity #InfoSec #CVE #RCE https://t.co/7zy5xJET0r

    Post summary

    Chrome 146 security update addresses three critical RCE bugs—CVE-2026-4439, CVE-2026-4440, and CVE-2026-4441—and urges users to install the patch immediately.

    0000091
    4 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4441 Use after free in Base in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secu… https://www.cve.org/CVERecord?id=CVE-2026-4441

    Post summary

    The text discloses CVE‑2026‑4441 as a use‑after‑free flaw in Chrome that could enable heap corruption via crafted HTML, but it lacks any discussion of PoC, exploitation, or patching.

    00000113
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more