CVE-2026-4679Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 3 mentions (2026-03-24); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-24: 3Mentions · 2026-03-27: 1Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-27: 1Technical Details · 2026-03-31: 103-2403-2703-31
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure2General1
2026-03-271
General1
2026-03-311
Patch1
Full discourse5 posts
  • iototsecnews@iototsecnews
    Patch

    Google Chrome の脆弱性 8件が修正:リモート・コード実行などの可能性 https://iototsecnews.jp/2026/03/24/chrome-security-update-fixes-8-vulnerabilities-that-could-enable-remote-code-execution/ 訳者後書:今回のアップデートで修正された脆弱性の多くは、メモリ管理の不備に起因しています。たとえば、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-4673/CVE-2026-4675 は、確保された領域を超えてデータが書き込まれることで発動されます。また、解放後メモリ使用 (use-after-free) の脆弱性 CVE-2026-4676/CVE-2026-4678/CVE-2026-4680 は、すでに解放されたメモリ領域にプログラムがアクセスし続けることで発動します。その他にも、境界外読み取りの脆弱性 CVE-2026-4674/CVE-2026-4677 や、整数オーバーフローの脆弱性 CVE-2026-4679 などは、メモリの扱いにおける予期せぬ動作を生じます。こうした低レイヤーでの管理ミスが、攻撃者にシステム制御を許すきっかけとなります。ご利用のチームは、ご注意ください。 #Chrome #CVE20264673 #CVE20264674 #CVE20264675 #CVE20264676 #CVE20264677 #CVE20264678 #CVE20264679 #CVE20264680 #Google #Vulnerability

    Post summary

    The article reports that Google Chrome has released a security update fixing eight CVEs that involve memory‑management flaws, explains the vulnerability types, and urges teams to apply the patch.

    01110239
    481 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-4679 Integer Overflow in Google Chrome Fonts Enables Remote Out-of-Bounds Memory Write https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4679

    Post summary

    The post references CVE‑2026‑4679, describing it as an integer overflow in Chrome fonts that allows a remote out‑of‑bounds memory write, but offers no proof of exploit, patch, or evidence of active attacks.

    0001051
    4.0K followersView on X
  • WindowsForum@windowsforum
    General

    🚨 Even after all these “mature browser” years, a fake HTML page can still try to scribble past memory in font rendering. Great reminder: Windows security is only as good as everyone’s patches. https://windowsforum.com/threads/cve-2026-4679-chrome-fonts-integer-overflow-fixed-in-146-0-7680-165.407989/ #ChromeSecurity #WindowsPatching #BrowserMemorySafety https://t.co/FZfjKGgts3

    Post summary

    The tweet references CVE‑2026‑4679, an integer‑overflow flaw in Chrome font rendering, and serves as a reminder that patching is essential.

    0000057
    1.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4679 Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium… https://www.cve.org/CVERecord?id=CVE-2026-4679

    Post summary

    The text announces CVE-2026-4679, describing an integer overflow in Chrome fonts that allows a remote attacker to cause an out‑of‑bounds memory write through a crafted HTML page.

    00000134
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4679 - High Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) https://www.thehackerwire.com/vulnerability/CVE-2026-4679/ https://t.co/Ahd0QLyH6f

    Post summary

    The tweet announces CVE‑2026‑4679, a high‑severity integer overflow in Chrome that allows remote memory writes via crafted HTML, without providing PoC, exploit code, or patch details.

    0000053
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more