CVE-2026-4677Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-24); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-24: 4Mentions · 2026-03-28: 1Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-24: 4Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 103-2403-2803-31
Signal classification3 categories
Patch
350.0%
Disclosure
233.3%
General
116.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-244
Disclosure2General1Patch1
2026-03-281
Patch1
2026-03-311
Patch1
Full discourse6 posts
  • iototsecnews@iototsecnews
    Patch

    Google Chrome の脆弱性 8件が修正:リモート・コード実行などの可能性 https://iototsecnews.jp/2026/03/24/chrome-security-update-fixes-8-vulnerabilities-that-could-enable-remote-code-execution/ 訳者後書:今回のアップデートで修正された脆弱性の多くは、メモリ管理の不備に起因しています。たとえば、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-4673/CVE-2026-4675 は、確保された領域を超えてデータが書き込まれることで発動されます。また、解放後メモリ使用 (use-after-free) の脆弱性 CVE-2026-4676/CVE-2026-4678/CVE-2026-4680 は、すでに解放されたメモリ領域にプログラムがアクセスし続けることで発動します。その他にも、境界外読み取りの脆弱性 CVE-2026-4674/CVE-2026-4677 や、整数オーバーフローの脆弱性 CVE-2026-4679 などは、メモリの扱いにおける予期せぬ動作を生じます。こうした低レイヤーでの管理ミスが、攻撃者にシステム制御を許すきっかけとなります。ご利用のチームは、ご注意ください。 #Chrome #CVE20264673 #CVE20264674 #CVE20264675 #CVE20264676 #CVE20264677 #CVE20264678 #CVE20264679 #CVE20264680 #Google #Vulnerability

    Post summary

    The article reports that Google Chrome has patched eight memory‑management related CVEs, detailing the types of vulnerabilities but offering no PoC, exploit code or evidence of active exploitation.

    01110239
    481 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Google Chrome 146 patches eight high-severity memory-safety flaws including heap buffer overflows, use-after-free, and integer overflow bugs. Notable fixes: CVE-2026-4673 & CVE-2026-4677 in WebAudio. #Chrome146 #BugBounty #USA https://ift.tt/Yfl8ZBS

    Post summary

    Chrome 146 rollout includes patches for eight high‑severity memory‑safety vulnerabilities, notably CVE‑2026‑4673 and CVE‑2026‑4677 in WebAudio, addressing heap overflows, use‑after‑free, and integer overflow issues.

    00001112
    3.8K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔥 Microsoft flagging a Chrome WebAudio out-of-bounds read is the reminder: the web isn’t sandboxed enough, and sound is how attackers slip in. Patch Chrome now—before your speakers get hacked. https://windowsforum.com/threads/cve-2026-4677-high-severity-chrome-webaudio-bug-patch-to-146-0-7680-165-now.408071/ #EnterprisePatching #ChromeSecurity #WebaudioVulnerability https://t.co/VkYZCJe78T

    Post summary

    The post announces Microsoft’s flagging of CVE‑2026‑4677, a high‑severity out‑of‑bounds read in Chrome’s WebAudio, and urges users to patch to the latest Chrome version.

    0000058
    1.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4677 Out-of-Bounds Memory Read Vulnerability in Google Chrome WebAudio ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4677 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post announces CVE-2026-4677 as an out‑of‑bounds memory read in Google Chrome WebAudio, linking to a vulnerability detail page. No further exploitation or mitigation information is provided.

    0000033
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4677 Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML p… https://www.cve.org/CVERecord?id=CVE-2026-4677

    Post summary

    Announces CVE-2026-4677, detailing an out‑of‑bounds memory read in Chrome’s WebAudio with no exploit or patch information provided.

    00000123
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4677 - High Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security ... https://www.thehackerwire.com/vulnerability/CVE-2026-4677/ https://t.co/U7qVqKBA3Y

    Post summary

    A new high‑severity CVE (CVE‑2026‑4677) affecting Chrome’s WebAudio allows remote attackers to perform out‑of‑bounds memory reads via crafted HTML pages.

    0000039
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more