CVE-2026-2315
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-2315 is an inappropriate implementation vulnerability in the WebGPU component of Google Chrome that allows a remote attacker to potentially perform out-of-bounds memory access via a crafted HTML page. It affects all versions of Google Chrome prior to 145.0.7632.45 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on January 27, 2026, and patched with the Chrome 145 stable channel release on February 10, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Feedly).

Technical details

The root cause is an inappropriate implementation in Chrome's WebGPU subsystem (CWE classification consistent with improper input handling or boundary enforcement), which can be triggered by a specially crafted HTML page containing malicious WebGPU API calls. An attacker exploits this by hosting a malicious webpage and luring a victim to visit it, at which point the browser processes the crafted content and may perform out-of-bounds memory reads or writes within the renderer process. The precondition for exploitation is user interaction — the victim must navigate to the attacker-controlled page — and no authentication or elevated privileges are required on the attacker's side. Bug details remain restricted pending broad user update, as is standard Google practice (Chrome Releases).

Impact

Successful exploitation could result in high confidentiality, integrity, and availability impacts, potentially enabling unauthorized disclosure of sensitive browser memory contents, modification of data or system behavior, and browser crashes or denial of service. Because the vulnerability resides in the renderer process, exploitation could serve as a stepping stone toward sandbox escape if chained with additional vulnerabilities, potentially leading to arbitrary code execution on the host system. The scope is limited to the affected Chrome browser instance, but the breadth of Chrome's user base makes this a high-impact vulnerability at scale (Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability was discovered and reported internally by Google, which reduces the likelihood of immediate weaponization. The EPSS score is approximately 0.02% (0.000200), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Mitigation and workarounds

Google has released Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac) which resolves this vulnerability. Users and administrators should immediately update Chrome to version 145.0.7632.45 or later via the browser's built-in update mechanism or enterprise deployment tools. As an interim measure prior to patching, organizations should advise users to avoid visiting untrusted or unknown websites and consider restricting access to non-essential web browsing. Downstream distributions including Debian, openSUSE, Fedora, and Chainguard have also released updated Chromium packages addressing this issue (Chrome Releases).

Community reactions

The Chrome 145 update received coverage from multiple security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress, which highlighted the release as patching 11 vulnerabilities including three high-severity flaws. A Reddit thread on r/pwnhub noted the Chrome 145 fixes. Check Point Research included the vulnerability in their February 16, 2026 threat intelligence report. Community reaction was generally focused on the broader Chrome 145 security update rather than this specific CVE, with emphasis on the importance of prompt patching (Chrome Releases, SecurityOnline).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-85050CRITICAL9.6
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 03, 2026
CVE-2026-85053HIGH8.8
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesSep 03, 2026
CVE-2026-85051HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 03, 2026
CVE-2026-85049HIGH8.8
  • Google Chrome logoGoogle Chrome
  • webkitgtk4-plugin-process-gtk2
NoYesSep 03, 2026
CVE-2026-85052LOW3.1
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesSep 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management