CVE-2026-4680Disclosure(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-03-24); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-03-24: 5Mentions · 2026-03-25: 1Mentions · 2026-03-28: 1Mentions · 2026-03-31: 1Active Exploitation · 2026-03-24: 1Patch / Workaround · 2026-03-31: 1Technical Details · 2026-03-24: 3Technical Details · 2026-03-25: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 103-2403-2503-2803-31
Signal classification4 categories
Disclosure
562.5%
Active Exploitation
112.5%
General
112.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-245
Active Exploitation1Disclosure4
2026-03-251
Disclosure1
2026-03-281
General1
2026-03-311
Patch1
Full discourse8 posts
  • iototsecnews@iototsecnews
    Patch

    Google Chrome の脆弱性 8件が修正:リモート・コード実行などの可能性 https://iototsecnews.jp/2026/03/24/chrome-security-update-fixes-8-vulnerabilities-that-could-enable-remote-code-execution/ 訳者後書:今回のアップデートで修正された脆弱性の多くは、メモリ管理の不備に起因しています。たとえば、ヒープバッファ・オーバーフローの脆弱性 CVE-2026-4673/CVE-2026-4675 は、確保された領域を超えてデータが書き込まれることで発動されます。また、解放後メモリ使用 (use-after-free) の脆弱性 CVE-2026-4676/CVE-2026-4678/CVE-2026-4680 は、すでに解放されたメモリ領域にプログラムがアクセスし続けることで発動します。その他にも、境界外読み取りの脆弱性 CVE-2026-4674/CVE-2026-4677 や、整数オーバーフローの脆弱性 CVE-2026-4679 などは、メモリの扱いにおける予期せぬ動作を生じます。こうした低レイヤーでの管理ミスが、攻撃者にシステム制御を許すきっかけとなります。ご利用のチームは、ご注意ください。 #Chrome #CVE20264673 #CVE20264674 #CVE20264675 #CVE20264676 #CVE20264677 #CVE20264678 #CVE20264679 #CVE20264680 #Google #Vulnerability

    Post summary

    Google Chrome released an update that patches eight CVEs mainly involving memory‑management bugs such as heap buffer overflows and use‑after‑free conditions, which could allow remote code execution. The article outlines the vulnerability types and notes the update mitigates them.

    01110239
    481 followersView on X
  • WindowsForum@windowsforum
    General

    🧨 Chrome’s FedCM use-after-free (CVE-2026-4680) screams “patch fast.” If a crafted HTML page can hit RCE—even in the sandbox—your browser’s not your safe word. https://windowsforum.com/threads/chrome-fedcm-use-after-free-cve-2026-4680-patch-before-146-0-7680-165.408068/ #ChromeUpdate #ChromiumVulnerabilities #Cve20264680 #FedcmSecurity https://t.co/gnYvqPZkR2

    Post summary

    The tweet flags Chrome’s FedCM use‑after‑free (CVE‑2026‑4680) as a potential RCE risk and urges people to patch, but provides no PoC, exploit code, or patch details.

    0000048
    1.0K followersView on X
  • Nicolas Coolman@NicolasCoolman
    Disclosure

    📢 Google Chrome en Alerte : Faille Critique CVE-2026-4680 Permet l’Exécution de Code à Distance ! https://t.co/TbHrG6Ra8B

    Post summary

    The tweet announces a newly disclosed critical vulnerability (CVE-2026-4680) in Google Chrome that permits remote code execution, but does not provide exploit details, active exploitation evidence, or patch information.

    0000042
    84 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Google Chrome (CVE-2026-4680) https://vuldb.com/?ctiid.352620

    Post summary

    The CTI team has detected numerous activities targeting Google Chrome CVE-2026-4680, indicating that this vulnerability is currently being exploited in the wild.

    0000053
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4680 Use-After-Free in Google Chrome FedCM Enables Remote Code Execution via Crafted HTML https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4680

    Post summary

    The notice reports CVE‑2026‑4680, a use‑after‑free bug in Google Chrome FedR that permits remote code execution through crafted HTML, with no mention of PoC, exploitation, patches, or false‑positive status.

    0000045
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4680 Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium… https://www.cve.org/CVERecord?id=CVE-2026-4680

    Post summary

    The entry details a use‑after‑free vulnerability (CVE‑2026‑4680) in Google Chrome’s FedCM that allows a remote attacker to run arbitrary code inside a sandbox through a crafted HTML page; no PoC, exploit code, patch, or active exploitation is reported.

    00000143
    56.8K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Google Chrome (CVE-2026-4680) https://vuldb.com/?id.352620

    Post summary

    The post announces a new CVE-2026-4680 vulnerability in Google Chrome, providing a reference to a Vuldb entry but no additional exploitation or mitigation details.

    0000063
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4680 - High Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) https://www.thehackerwire.com/vulnerability/CVE-2026-4680/ https://t.co/XZijyS5PGR

    Post summary

    The text announces CVE-2026-4680, a use‑after‑free flaw in FedCM before Chrome 146, enabling remote code execution via a crafted HTML page, but it does not disclose a PoC, patch, or evidence of active exploitation.

    0000042
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more