
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2650 is a heap buffer overflow vulnerability in the Media component of Google Chrome, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by Google internally on January 18, 2026, and patched on February 18, 2026, with the release of Chrome 145.0.7632.109. Affected products include Google Chrome prior to version 145.0.7632.109 and Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Advisory, Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) in Chrome's Media component. An attacker can deliver a specially crafted HTML page to a victim, triggering a heap buffer overflow when the browser processes malicious media content, potentially leading to heap corruption and arbitrary code execution. Exploitation requires no special privileges and no prior authentication, but does require user interaction — specifically, a user visiting or being redirected to a malicious webpage. The bug was discovered internally by Google and is associated with CAPEC-92 (Forced Integer Overflow) as a related attack pattern (Chrome Advisory, Feedly).
Successful exploitation can result in high-severity impacts across confidentiality, integrity, and availability — consistent with the CVSS v3.1 score of 8.8. An attacker who achieves heap corruption may be able to execute arbitrary code in the context of the Chrome renderer process, potentially enabling data theft, browser session hijacking, or further lateral movement if combined with a sandbox escape. The attack is network-deliverable and requires only that a user open a malicious webpage, making it broadly applicable against Chrome and Chromium-based browser users (Chrome Advisory, Feedly).
chrome.exe / chrome on Linux/macOS) spawning unexpected child processes or exhibiting abnormal memory usage patterns; crashes or unexpected termination of Chrome renderer processes.Google has released a patch in Chrome stable channel version 145.0.7632.109 (Linux) and 145.0.7632.109/110 (Windows/Mac), released February 18, 2026. Microsoft has also issued an update for Edge (Chromium-based) addressing this vulnerability. Users and organizations should update Chrome and all Chromium-based browsers to the latest available version immediately. No configuration-based workaround is available; patching is the only effective remediation (Chrome Advisory, Microsoft MSRC).
Security news outlets including CyberSecurityNews, GBHackers, and SecurityOnline.info covered the Chrome emergency update, framing it alongside the co-patched High-severity PDFium (CVE-2026-2648) and V8 (CVE-2026-2649) flaws. NotebookCheck reported that Google scrambled to patch flaws as exploit code for related vulnerabilities went public. The Hacker News included the update in its weekly security recap. Downstream Linux distributions (Debian, openSUSE, Fedora) and vendors including Palo Alto Networks and Splunk issued their own advisories incorporating the fix (SecurityOnline, CyberSecurityNews, Hacker News Recap).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."