
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2315 is an inappropriate implementation vulnerability in the WebGPU component of Google Chrome that allows a remote attacker to potentially perform out-of-bounds memory access via a crafted HTML page. It affects all versions of Google Chrome prior to 145.0.7632.45 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on January 27, 2026, and patched with the Chrome 145 stable channel release on February 10, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Feedly).
The root cause is an inappropriate implementation in Chrome's WebGPU subsystem (CWE classification consistent with improper input handling or boundary enforcement), which can be triggered by a specially crafted HTML page containing malicious WebGPU API calls. An attacker exploits this by hosting a malicious webpage and luring a victim to visit it, at which point the browser processes the crafted content and may perform out-of-bounds memory reads or writes within the renderer process. The precondition for exploitation is user interaction — the victim must navigate to the attacker-controlled page — and no authentication or elevated privileges are required on the attacker's side. Bug details remain restricted pending broad user update, as is standard Google practice (Chrome Releases).
Successful exploitation could result in high confidentiality, integrity, and availability impacts, potentially enabling unauthorized disclosure of sensitive browser memory contents, modification of data or system behavior, and browser crashes or denial of service. Because the vulnerability resides in the renderer process, exploitation could serve as a stepping stone toward sandbox escape if chained with additional vulnerabilities, potentially leading to arbitrary code execution on the host system. The scope is limited to the affected Chrome browser instance, but the breadth of Chrome's user base makes this a high-impact vulnerability at scale (Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability was discovered and reported internally by Google, which reduces the likelihood of immediate weaponization. The EPSS score is approximately 0.02% (0.000200), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
Google has released Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac) which resolves this vulnerability. Users and administrators should immediately update Chrome to version 145.0.7632.45 or later via the browser's built-in update mechanism or enterprise deployment tools. As an interim measure prior to patching, organizations should advise users to avoid visiting untrusted or unknown websites and consider restricting access to non-essential web browsing. Downstream distributions including Debian, openSUSE, Fedora, and Chainguard have also released updated Chromium packages addressing this issue (Chrome Releases).
The Chrome 145 update received coverage from multiple security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress, which highlighted the release as patching 11 vulnerabilities including three high-severity flaws. A Reddit thread on r/pwnhub noted the Chrome 145 fixes. Check Point Research included the vulnerability in their February 16, 2026 threat intelligence report. Community reaction was generally focused on the broader Chrome 145 security update rather than this specific CVE, with emphasis on the importance of prompt patching (Chrome Releases, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."