
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2314 is a heap buffer overflow vulnerability in the Codecs component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported internally by Google on January 26, 2026, and disclosed publicly on February 10, 2026, as part of the Chrome 145 stable channel release. The vulnerability affects all Google Chrome versions prior to 145.0.7632.45, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Feedly).
The root cause is a heap-based buffer overflow (CWE-122) combined with an out-of-bounds write (CWE-787) in Chrome's Codecs component, which handles media decoding and encoding operations. An attacker can exploit this by crafting a malicious HTML page that triggers improper memory operations within the Codecs subsystem, potentially leading to heap corruption. Exploitation requires user interaction — specifically, a victim must visit or be redirected to the attacker-controlled page. No bug bounty reward was listed (marked N/A), and the bug was discovered internally by Google, suggesting it may have been found via fuzzing tools such as AddressSanitizer or libFuzzer, which Google routinely uses for Chrome security testing (Chrome Releases).
Successful exploitation could allow a remote attacker to trigger heap memory corruption in the Chrome browser process, potentially resulting in sensitive data leakage, modification of browser content, or browser crashes. In a worst-case scenario, heap corruption of this nature can be leveraged to achieve arbitrary code execution within the browser's renderer or browser process, depending on sandbox bypass capabilities. The vulnerability affects confidentiality, integrity, and availability at a high level, and impacts all platforms where Chrome prior to 145.0.7632.45 is deployed, including Windows, macOS, Linux, and ChromeOS (Feedly, Chrome Releases).
Google has released Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac) to address this vulnerability; users should update immediately via Chrome's built-in update mechanism or by downloading from the official Chrome website (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update once available via the Microsoft Security Response Center (Microsoft MSRC). As an interim measure, organizations should consider restricting access to untrusted or unknown websites and ensuring enterprise Chrome deployments are managed with automatic updates enabled. Chromium-based distributions (Debian, Fedora, openSUSE) have also released updated packages addressing this CVE.
The Chrome 145 security update received broad coverage from cybersecurity news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress, which highlighted the three high-severity flaws patched in the release (SecurityOnline). Check Point Research included the vulnerability in its February 16, 2026 threat intelligence report (Check Point). Community discussion on Reddit's r/pwnhub noted the significance of the 11 vulnerabilities fixed in Chrome 145. No major controversy or unusual researcher commentary was noted regarding this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."