CVE-2026-4676Disclosure(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 4 mentions (2026-03-24); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-24: 4Mentions · 2026-03-25: 1Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1Active Exploitation · 2026-04-01: 1Patch / Workaround · 2026-03-31: 2Technical Details · 2026-03-24: 3Technical Details · 2026-03-25: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 103-2403-2503-3104-01
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
Active Exploitation
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-244
Disclosure4
2026-03-251
Disclosure1
2026-03-312
Patch2
2026-04-011
Active Exploitation1
Full discourse8 posts
  • iototsecnews@iototsecnews
    Patch

    Google Chrome の脆弱性 8件が修正:リモート・コード実行などの可能性 https://iototsecnews.jp/2026/03/24/chrome-security-update-fixes-8-vulnerabilities-that-could-enable-remote-code-execution/ 訳者後書:今回のアップデートで修正された脆弱性の多くは、メモリ管理の不備に起因しています。たとえば、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-4673/CVE-2026-4675 は、確保された領域を超えてデータが書き込まれることで発動されます。また、解放後メモリ使用 (use-after-free) の脆弱性 CVE-2026-4676/CVE-2026-4678/CVE-2026-4680 は、すでに解放されたメモリ領域にプログラムがアクセスし続けることで発動します。その他にも、境界外読み取りの脆弱性 CVE-2026-4674/CVE-2026-4677 や、整数オーバーフローの脆弱性 CVE-2026-4679 などは、メモリの扱いにおける予期せぬ動作を生じます。こうした低レイヤーでの管理ミスが、攻撃者にシステム制御を許すきっかけとなります。ご利用のチームは、ご注意ください。 #Chrome #CVE20264673 #CVE20264674 #CVE20264675 #CVE20264676 #CVE20264677 #CVE20264678 #CVE20264679 #CVE20264680 #Google #Vulnerability

    Post summary

    The article announces the Chrome update that patches eight memory‑management CVEs, provides brief technical details, but does not mention active exploitation or PoC.

    01110239
    481 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2026-4676 in Chrome's Dawn component to achieve sandbox escape and lateral movement. The use-after-free flaw enabled arbitrary code execution via crafted HTML pages. Runtime segmentation helps contain post-compromise activity in browser-based attacks. #ZeroDay 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/chrome-2026-dawn-use-after-free

    Post summary

    Report confirms that CVE‑2026‑4676 is being actively exploited in Chrome via a use‑after‑free flaw that allows sandbox escape and code execution over crafted HTML pages, with runtime segmentation mitigating post‑compromise activity.

    0000058
    1.9K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔥 Chrome still has UAF in Dawn? Cool. Meanwhile Windows folks just want fewer crashes, not “maybe sandbox escape” roulette. Update yesterday—security hygiene isn’t optional. https://windowsforum.com/threads/cve-2026-4676-dawn-use-after-free-chrome-146-0-7680-165-security-fix.408652/ #BrowserVulnerability #ChromeSecurity #Cve20264676 #UseAfterFree https://t.co/qO4zwqrakI

    Post summary

    CVE-2026-4676 is a use‑after‑free flaw in Chrome’s Dawn engine; a patch is available as referenced in the linked forum thread, with no publicly documented PoC, exploit, or active exploitation reported.

    0000066
    1.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4676 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Google Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4676 #CVE-2026-4676 #CVE #High #Google #CyberSecurity #InfoSec https://t.co/hBM2bUVTeb

    Post summary

    The tweet announces CVE‑2026‑4676 with severity 8.8, risk level high, and points to the NVD entry.

    0000045
    114 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4676 Use-After-Free Vulnerability in Google Chrome Dawn Renderer Enables Sandbox Escape https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4676

    Post summary

    A new use‑after‑free vulnerability (CVE‑2026‑4676) in Google Chrome’s Dawn Renderer that can lead to sandbox escape is announced; no further details on PoC, exploit code, or mitigation are provided.

    0000037
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4676 Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium sec… https://www.cve.org/CVERecord?id=CVE-2026-4676

    Post summary

    The passage describes a use‑after‑free flaw in Chrome’s Dawn engine that could lead to sandbox escape through a crafted HTML page, but does not mention a PoC, exploit code, or patch details.

    00000135
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4676 - High Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) https://www.thehackerwire.com/vulnerability/CVE-2026-4676/ https://t.co/NEetSmdQsZ

    Post summary

    The tweet announces CVE-2026-4676, detailing a use-after-free sandbox escape flaw in Google Chrome before version 146.0.7680.165, but does not provide PoC, exploit code, or patch information.

    0000044
    145 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Google Chrome (CVE-2026-4676) https://vuldb.com/?id.352617

    Post summary

    The statement announces a new vulnerability (CVE-2026-4676) for Google Chrome, noting increased severity, but provides no additional technical detail, PoC, exploit, or mitigation information.

    0000065
    2.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more