CVE-2026-4675Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-24); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-03-24: 4Mentions · 2026-03-25: 1Mentions · 2026-03-27: 1Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-24: 4Technical Details · 2026-03-27: 1Technical Details · 2026-03-31: 103-2403-2503-2703-31
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-244
Disclosure4
2026-03-251
General1
2026-03-271
General1
2026-03-311
Patch1
Full discourse7 posts
  • iototsecnews@iototsecnews
    Patch

    Google Chrome の脆弱性 8件が修正:リモート・コード実行などの可能性 https://iototsecnews.jp/2026/03/24/chrome-security-update-fixes-8-vulnerabilities-that-could-enable-remote-code-execution/ 訳者後書:今回のアップデートで修正された脆弱性の多くは、メモリ管理の不備に起因しています。たとえば、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-4673/CVE-2026-4675 は、確保された領域を超えてデータが書き込まれることで発動されます。また、解放後メモリ使用 (use-after-free) の脆弱性 CVE-2026-4676/CVE-2026-4678/CVE-2026-4680 は、すでに解放されたメモリ領域にプログラムがアクセスし続けることで発動します。その他にも、境界外読み取りの脆弱性 CVE-2026-4674/CVE-2026-4677 や、整数オーバーフローの脆弱性 CVE-2026-4679 などは、メモリの扱いにおける予期せぬ動作を生じます。こうした低レイヤーでの管理ミスが、攻撃者にシステム制御を許すきっかけとなります。ご利用のチームは、ご注意ください。 #Chrome #CVE20264673 #CVE20264674 #CVE20264675 #CVE20264676 #CVE20264677 #CVE20264678 #CVE20264679 #CVE20264680 #Google #Vulnerability

    Post summary

    The article announces that eight memory‑management bugs in Chrome have been fixed in a recent update, detailing the types of vulnerabilities and urging teams to apply the patch.

    01110239
    481 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4675 Heap Buffer Overflow in Google Chrome WebGL Enables Remote Out-of-Bounds Memory Read https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4675

    Post summary

    The text announces a heap buffer overflow vulnerability in Chrome WebGL that allows out-of-bounds memory reads, but does not mention any PoC, exploit code, or mitigation.

    0000139
    4.0K followersView on X
  • WindowsForum@windowsforum
    General

    🚨 Chrome’s WebGL heap overflow? Cool cool—another day, another “update now” moment. If a crafted HTML page can pop your browser, everyone’s playing security roulette. https://windowsforum.com/threads/chrome-webgl-cve-2026-4675-heap-overflow-update-to-146-0-7680-165-now.407986/ #ChromeSecurity #BrowserPatching #WebglVulnerability #Cve20264675 https://t.co/p7QLHJPef0

    Post summary

    The tweet warns that Chrome has a WebGL heap overflow vulnerability (CVE‑2026‑4675) and urges users to update, but provides only basic technical details and no evidence of exploits, patches, or active attacks.

    0000048
    1.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4675 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Google Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4675 #CVE-2026-4675 #CVE #High #Google #CyberSecurity #InfoSec https://t.co/rxv9o1vzmk

    Post summary

    The tweet announces a new CVE and its severity, linking to the NVD entry, but offers no technical, exploit, or patch details.

    0000033
    114 followersView on X
  • Fernando Karl@fernandokarl
    Disclosure

    🚨 Critical Alert! CVE-2026-4675 scores CVSS 10.0 & 8.8—high risk of remote exploitation without authentication! Ensure your systems are patched and reduce exposure. Don't wait, act now! 🛡️ Stay informed and protect your assets: https://www.tenable.com/cve/CVE-2026-4675 #CyberSecurity #InfoSec

    Post summary

    The message announces CVE-2026-4675 with high CVSS scores and stresses the need to patch systems, but no PoC, exploit code, or active exploitation evidence is provided.

    0000051
    258 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4675 Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chrom… https://www.cve.org/CVERecord?id=CVE-2026-4675

    Post summary

    The entry outlines a heap buffer overflow in Chrome’s WebGL that permits an out-of-bounds memory read through a crafted HTML page, but provides no details on PoC, exploit code, active exploitation, or patches.

    00000140
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4675 - High Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: H... https://www.thehackerwire.com/vulnerability/CVE-2026-4675/ https://t.co/ZhRFfBoDXn

    Post summary

    A high‑severity heap buffer overflow (CVE‑2026‑4675) in Chrome’s WebGL is disclosed, detailing the vulnerability type and affected version but offering no PoC, exploit, or patch information.

    0000041
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more