CVE-2026-2321
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-2321 is a use-after-free vulnerability in the Ozone component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. The attacker must convince a user to engage in specific UI gestures to trigger the flaw. It affects all versions of Google Chrome prior to 145.0.7632.45 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on 2025-11-18 and patched on February 10, 2026, with public disclosure on February 11, 2026. It carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal security scale (Chrome Releases, Feedly).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Ozone platform abstraction layer, which handles windowing and UI input on Linux-based systems. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the contents of that memory region and redirect program execution. Exploitation requires delivery via a crafted HTML page and user interaction in the form of specific UI gestures, making it a network-delivered, user-interaction-required attack. No public technical write-up or proof-of-concept code has been identified at this time (Chrome Releases, Feedly).

Impact

Successful exploitation could lead to heap corruption, with potential consequences including arbitrary code execution or denial of service within the context of the Chrome browser process. Given Chrome's sandboxing architecture, a full system compromise would typically require chaining this vulnerability with a sandbox escape; however, code execution within the renderer or browser process could still expose sensitive user data, session tokens, and browsing history. The confidentiality, integrity, and availability impacts are all rated High (Feedly).

Mitigation and workarounds

Google has released a patch in Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac), which addresses this and 10 other security vulnerabilities. Users and administrators should update all Chrome installations to version 145.0.7632.45 or later immediately. As a general precaution, users should avoid visiting untrusted websites and be wary of pages that prompt unusual UI interactions. Downstream distributions including Debian, openSUSE, Fedora, and ChromeOS have also released updated Chromium packages incorporating this fix (Chrome Releases).

Community reactions

The Chrome 145 security update received coverage from several cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, which highlighted the 11 security fixes included in the release. Social media accounts such as TheHackerWire shared the update on Bluesky and Mastodon. Security vendors including Tenable (Nessus) and Qualys published detection plugins for the vulnerability shortly after disclosure. Palo Alto Networks also issued an advisory (PAN-SA-2026-0003) as part of their monthly Chromium vulnerability update for March 2026 (Chrome Releases, Palo Alto Advisory).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15767HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui-debuginfo
NoYesJul 14, 2026
CVE-2026-15769HIGH8.3
  • Google Chrome logoGoogle Chrome
  • chromium-common
NoYesJul 14, 2026
CVE-2026-15770MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromedriver
NoYesJul 14, 2026
CVE-2026-15768MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesJul 14, 2026
CVE-2026-15766MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium-qt5-ui-debuginfo
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management