CVE-2026-4673Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

3.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 4d ago at 4 mentions (2026-03-24); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-03-24: 4Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-24: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-25: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-31: 103-2403-2503-2603-2703-31
Signal classification2 categories
Patch
555.6%
Disclosure
444.4%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-244
Disclosure3Patch1
2026-03-252
Disclosure1Patch1
2026-03-261
Patch1
2026-03-271
Patch1
2026-03-311
Patch1
Full discourse9 posts
  • iototsecnews@iototsecnews
    Patch

    Google Chrome の脆弱性 8件が修正:リモート・コード実行などの可能性 https://iototsecnews.jp/2026/03/24/chrome-security-update-fixes-8-vulnerabilities-that-could-enable-remote-code-execution/ 訳者後書:今回のアップデートで修正された脆弱性の多くは、メモリ管理の不備に起因しています。たとえば、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-4673/CVE-2026-4675 は、確保された領域を超えてデータが書き込まれることで発動されます。また、解放後メモリ使用 (use-after-free) の脆弱性 CVE-2026-4676/CVE-2026-4678/CVE-2026-4680 は、すでに解放されたメモリ領域にプログラムがアクセスし続けることで発動します。その他にも、境界外読み取りの脆弱性 CVE-2026-4674/CVE-2026-4677 や、整数オーバーフローの脆弱性 CVE-2026-4679 などは、メモリの扱いにおける予期せぬ動作を生じます。こうした低レイヤーでの管理ミスが、攻撃者にシステム制御を許すきっかけとなります。ご利用のチームは、ご注意ください。 #Chrome #CVE20264673 #CVE20264674 #CVE20264675 #CVE20264676 #CVE20264677 #CVE20264678 #CVE20264679 #CVE20264680 #Google #Vulnerability

    Post summary

    The post announces that eight Chrome CVEs have been patched, detailing the memory‑management bug types and the corrections, but provides no exploit code or evidence of active attacks.

    01110239
    481 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Google Chrome 146 patches eight high-severity memory-safety flaws including heap buffer overflows, use-after-free, and integer overflow bugs. Notable fixes: CVE-2026-4673 & CVE-2026-4677 in WebAudio. #Chrome146 #BugBounty #USA https://ift.tt/Yfl8ZBS

    Post summary

    Chrome 146 includes patches for CVE-2026-4673 and CVE-2026-4677, addressing high‑severity memory‑safety bugs such as heap buffer overflows, use‑after‑free, and integer overflows.

    00001112
    3.8K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 Chrome WebAudio just got a heap overflow. Because apparently audio needs memory-safety too. Patch fast—one malicious page can go from “listen” to “owned.” #Windows #Security https://windowsforum.com/threads/cve-2026-4673-chrome-webaudio-heap-overflow-fix-now-146-0-7680-165.407983/ #ChromeSecurity #WindowsPatching #WebaudioVulnerability #HeapBufferOverflow https://t.co/1GOnyF4G9l

    Post summary

    A newly disclosed Chrome WebAudio heap overflow (CVE‑2026‑4673) is highlighted, with an urgent call for patching to prevent potential full compromise by malicious webpages.

    0000050
    1.0K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    The #Fedora 44 Chromium update is out with fixes for 8 high-severity CVEs, including CVE-2026-4673. Read more: 👉 https://tinyurl.com/mr3kedjt #Security https://t.co/b1UzHEjB2H

    Post summary

    Fedora 44’s Chromium update includes fixes for eight high‑severity CVEs, notably CVE‑2026‑4673, confirming a patch release.

    0000057
    1.5K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの高深刻度 脆弱性 8件を修正(CVE-2026-4673〜4680) https://rocket-boys.co.jp/security-measures-lab/sada-hospital-nurse-sns-post-medical-record-image-leak-privacy-risk-2/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The notice reports that Google Chrome has patched eight high‑severity vulnerabilities (CVE‑2026‑4673 to 4680), with no mention of PoC, exploit code, or active exploitation.

    00000136
    340 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4673 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Google Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4673 #CVE-2026-4673 #CVE #High #Google #CyberSecurity #InfoSec https://t.co/UsI4zRtQrI

    Post summary

    The tweet announces a new CVE (CVE-2026-4673) affecting Google with severity 8.8, but provides no technical, exploit, or patch details.

    0000031
    114 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4673 Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (C… https://www.cve.org/CVERecord?id=CVE-2026-4673

    Post summary

    The text announces a heap buffer overflow vulnerability in Chrome’s WebAudio component (before 146.0.7680.165) that permits a remote attacker to perform an out‑of‑bounds memory write through a crafted HTML page.

    00000136
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4673 - High Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severit... https://www.thehackerwire.com/vulnerability/CVE-2026-4673/ https://t.co/72ZMv7roUV

    Post summary

    The post announces a heap buffer overflow in Chrome's WebAudio component that allows remote out‑of‑bounds memory writes via crafted HTML pages. It provides technical details but no evidence of active exploitation, patch, or exploit tool.

    0000044
    145 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Google Chrome (CVE-2026-4673) https://vuldb.com/?id.352578

    Post summary

    A severe vulnerability in Google Chrome (CVE-2026-4673) was announced, but the post contains no further exploitation details or mitigation advice.

    0000066
    2.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more