CVE-2026-4674Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-24); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-24: 3Mentions · 2026-03-25: 1Mentions · 2026-03-28: 1Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 103-2403-2503-2803-31
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure2General1
2026-03-251
Disclosure1
2026-03-281
Patch1
2026-03-311
Patch1
Full discourse6 posts
  • iototsecnews@iototsecnews
    Patch

    Google Chrome の脆弱性 8件が修正:リモート・コード実行などの可能性 https://iototsecnews.jp/2026/03/24/chrome-security-update-fixes-8-vulnerabilities-that-could-enable-remote-code-execution/ 訳者後書:今回のアップデートで修正された脆弱性の多くは、メモリ管理の不備に起因しています。たとえば、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-4673/CVE-2026-4675 は、確保された領域を超えてデータが書き込まれることで発動されます。また、解放後メモリ使用 (use-after-free) の脆弱性 CVE-2026-4676/CVE-2026-4678/CVE-2026-4680 は、すでに解放されたメモリ領域にプログラムがアクセスし続けることで発動します。その他にも、境界外読み取りの脆弱性 CVE-2026-4674/CVE-2026-4677 や、整数オーバーフローの脆弱性 CVE-2026-4679 などは、メモリの扱いにおける予期せぬ動作を生じます。こうした低レイヤーでの管理ミスが、攻撃者にシステム制御を許すきっかけとなります。ご利用のチームは、ご注意ください。 #Chrome #CVE20264673 #CVE20264674 #CVE20264675 #CVE20264676 #CVE20264677 #CVE20264678 #CVE20264679 #CVE20264680 #Google #Vulnerability

    Post summary

    The text reports that Google Chrome has released a patch fixing eight memory-management vulnerabilities, providing technical details but no proof of concept or active exploitation information.

    01110239
    481 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4674 Out of Bounds Read in Google Chrome Prior to 146.0.7680.165 Enables Remote Memory Access https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4674

    Post summary

    The post announces a newly disclosed CVE-2026-4674, describing an out-of-bounds read flaw in Chrome that could allow remote memory access, without detailing exploits, patches, or active attacks.

    0000138
    4.0K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 Patch Chrome ASAP: CVE-2026-4674 is a high-sev out-of-bounds read via CSS—aka “open a dodgy page, watch Windows do the tango.” Keep Chrome updated, folks. #Security #Windows https://windowsforum.com/threads/patch-chrome-now-cve-2026-4674-high-severity-css-out-of-bounds-read-win.408074/ #EnterprisePatching #ChromeSecurity #WindowsUpdates #Cve20264674 https://t.co/mWCNZIcBEr

    Post summary

    The tweet alerts Chrome users to a high‑severity out‑of‑bounds read CVE‑2026‑4674 via CSS and urges them to apply available patches promptly.

    0000056
    1.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4674 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Google Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4674 #CVE-2026-4674 #CVE #High #Google #CyberSecurity #InfoSec https://t.co/Spp251ZcKc

    Post summary

    The tweet announces CVE-2026-4674, a high-severity vulnerability affecting Google, but provides no more detail beyond the severity score.

    0000035
    114 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4674 Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium s… https://www.cve.org/CVERecord?id=CVE-2026-4674

    Post summary

    The text provides a concise disclosure of the CVE, detailing the vulnerability and the affected Chrome version range, but does not include PoC, exploit code, or active exploitation evidence.

    00000140
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-4674 - High Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) https://www.thehackerwire.com/vulnerability/CVE-2026-4674/ https://t.co/MvKmPVcRnY

    Post summary

    The notice reports a high‑severity out‑of‑bounds memory read in Google Chrome prior to version 146.0.7680.165, allowing remote attackers to craft an HTML page for out‑of‑bounds memory access, but it does not disclose a PoC, exploit code, or patch.

    0000049
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more