CVE-2026-4678Disclosure(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-03-24); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-24: 5Mentions · 2026-03-25: 1Mentions · 2026-03-31: 1Active Exploitation · 2026-03-24: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-25: 1Technical Details · 2026-03-31: 103-2403-2503-31
Signal classification4 categories
Disclosure
457.1%
Active Exploitation
114.3%
General
114.3%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-245
Active Exploitation1Disclosure3General1
2026-03-251
Disclosure1
2026-03-311
Patch1
Full discourse7 posts
  • iototsecnews@iototsecnews
    Patch

    Google Chrome の脆弱性 8件が修正:リモート・コード実行などの可能性 https://iototsecnews.jp/2026/03/24/chrome-security-update-fixes-8-vulnerabilities-that-could-enable-remote-code-execution/ 訳者後書:今回のアップデートで修正された脆弱性の多くは、メモリ管理の不備に起因しています。たとえば、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-4673/CVE-2026-4675 は、確保された領域を超えてデータが書き込まれることで発動されます。また、解放後メモリ使用 (use-after-free) の脆弱性 CVE-2026-4676/CVE-2026-4678/CVE-2026-4680 は、すでに解放されたメモリ領域にプログラムがアクセスし続けることで発動します。その他にも、境界外読み取りの脆弱性 CVE-2026-4674/CVE-2026-4677 や、整数オーバーフローの脆弱性 CVE-2026-4679 などは、メモリの扱いにおける予期せぬ動作を生じます。こうした低レイヤーでの管理ミスが、攻撃者にシステム制御を許すきっかけとなります。ご利用のチームは、ご注意ください。 #Chrome #CVE20264673 #CVE20264674 #CVE20264675 #CVE20264676 #CVE20264677 #CVE20264678 #CVE20264679 #CVE20264680 #Google #Vulnerability

    Post summary

    Google Chrome released an update fixing eight memory‑management CVEs, including heap overflows and use‑after‑free, with the article outlining the specific vulnerabilities and the patch.

    01110239
    481 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4678 Use-After-Free in WebGPU of Google Chrome Enables Remote Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4678

    Post summary

    The text announces CVE‑2026‑4678, a use‑after‑free vulnerability in Chrome’s WebGPU that allows remote code execution, with no PoC, active exploitation, patch, or debunking discussed.

    0001167
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4678 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Google Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4678 #CVE-2026-4678 #CVE #High #Google #CyberSecurity #InfoSec https://t.co/HfYZVVZAq7

    Post summary

    A brief alert announces CVE‑2026‑4678, affecting Google with a severity score of 8.8; it links to the NVD entry but provides no exploitation or patch information.

    0000035
    114 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting Google Chrome (CVE-2026-4678) https://vuldb.com/?ctiid.352619

    Post summary

    The report signals increased attacker activity targeting CVE-2026-4678 in Google Chrome, suggesting possible in‑the‑wild exploitation, but provides no technical or mitigation details.

    0000062
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4678 Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromiu… https://www.cve.org/CVERecord?id=CVE-2026-4678

    Post summary

    The text describes a use‑after‑free vulnerability in Chrome's WebGPU (CVE-2026-4678) that allows remote code execution via a crafted HTML page.

    00000137
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4678 - High Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) https://www.thehackerwire.com/vulnerability/CVE-2026-4678/ https://t.co/hGdBGSZZuO

    Post summary

    The tweet announces a new high‑severity use‑after‑free flaw in Chrome’s WebGPU allowing remote code execution via a crafted HTML page, without indicating current exploitation or mitigation.

    0000049
    145 followersView on X
  • VulDB 🛡@vuldb
    General

    The severity is increased for this new vulnerability affecting Google Chrome (CVE-2026-4678) https://vuldb.com/?id.352619

    Post summary

    A brief note indicating that the severity of CVE-2026-4678 affecting Google Chrome has been raised, with a link to a vulnerability database entry but no further technical or exploit information.

    0000064
    2.1K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more