
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1861 is a heap buffer overflow vulnerability in the libvpx video processing library as used in Google Chrome, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects Google Chrome versions prior to 144.0.7559.132 and Microsoft Edge (Chromium-based). The vulnerability was reported by Google on 2026-01-26 and publicly disclosed on 2026-02-03, with the patched stable channel release (144.0.7559.132/.133) announced on 2026-02-03. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), rooted in improper bounds checking within the libvpx library — an open-source video codec library used for VP8/VP9 encoding and decoding. An attacker can trigger the heap corruption by enticing a user to visit a specially crafted HTML page that causes Chrome to process malicious video content through libvpx. The attack vector is network-based, requires no privileges, but does require user interaction (e.g., visiting a malicious page). Because libvpx is a third-party library shared across multiple projects, Google initially restricted bug details until dependent projects could also apply fixes (Chrome Releases).
Successful exploitation could allow a remote attacker to achieve heap corruption, potentially leading to remote code execution, denial of service (browser crash), or information disclosure within the context of the Chrome browser process. The vulnerability affects confidentiality, integrity, and availability at a high level. While Chrome's sandbox mitigates the risk of full system compromise, a sandbox escape chained with this vulnerability could extend the impact to the underlying operating system (Chrome Releases, Microsoft MSRC).
chrome.exe, msedge.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, sh, bash) or crashing repeatedly with heap-related errors.Google has released Chrome 144.0.7559.132 (Linux) and 144.0.7559.132/.133 (Windows/Mac) which addresses this vulnerability. Microsoft has also released a corresponding update for Edge (Chromium-based). Users and administrators should update Chrome and Edge to the latest available versions immediately. No configuration-based workaround is available; patching is the only remediation. Organizations should prioritize this update given the High severity rating and the potential for remote code execution (Chrome Releases, Microsoft MSRC).
The vulnerability received broad coverage in the security community as part of the February 2026 Chrome stable channel update, which fixed two High-severity issues. Security outlets including BleepingComputer, CyberSecurityNews, GBHackers, and SecurityOnline.info reported on the update, noting the libvpx and V8 flaws as the primary concerns. The SANS Internet Storm Center also covered the February 2026 Patch Tuesday context in which this CVE appeared. Palo Alto Networks issued a Chromium monthly vulnerability update advisory (PAN-SA-2026-0002), and Sophos discussed it in their February Patch Tuesday blog. Community discussion on platforms like Mastodon and Reddit noted the importance of prompt patching given Chrome's wide deployment (Chrome Releases, Microsoft MSRC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."