
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4440 is an out-of-bounds read and write vulnerability in the WebGL component of Google Chrome that allows a remote attacker to perform arbitrary memory read/write operations via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153 and Microsoft Edge (Chromium-based). The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on February 20, 2026, and publicly disclosed on March 18–20, 2026, when Google released Chrome 146.0.7680.153 (Chrome Releases). It carries a CVSS v3.1 base score of 8.8 (High) (Feedly).
The vulnerability is rooted in improper bounds checking within Chrome's WebGL implementation, classified as CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write) (Feedly). An attacker can exploit this by serving a specially crafted HTML page containing malicious WebGL shader or buffer operations that trigger memory accesses outside allocated bounds. Exploitation requires user interaction — specifically, a victim must visit or be redirected to the attacker-controlled page — but no privileges or authentication are required on the attacker's side. A proof-of-concept exploit development server was observed publicly (BreakGlass Intel), and the Chromium issue tracker entry is referenced at https://issues.chromium.org/issues/485935305.
Successful exploitation enables arbitrary memory read and write within the browser process, which can lead to sensitive data disclosure (e.g., browser credentials, session tokens), integrity compromise, and potentially full remote code execution within the Chrome sandbox. All three CIA pillars — confidentiality, integrity, and availability — are rated High in the CVSS scoring (Feedly). While the browser sandbox limits direct OS-level impact, a chained sandbox escape could extend compromise to the underlying system. The vulnerability's network accessibility and low attack complexity make it practical for large-scale drive-by exploitation campaigns.
chrome.exe / chrome) spawning unexpected child processes or exhibiting abnormal memory usage spikes during WebGL-heavy page loads.chrome://crashes page correlating with visits to suspicious URLs.Google has released Chrome 146.0.7680.153 (Windows/Linux) and 146.0.7680.154 (Mac) which contain the fix for CVE-2026-4440 (Chrome Releases). Microsoft has also issued a corresponding update for Edge (Chromium-based) (Microsoft MSRC). Organizations should immediately update all Chrome and Edge installations to the patched versions. As a temporary workaround prior to patching, consider restricting access to untrusted or unknown websites via web filtering/proxy policies, and disabling WebGL via enterprise browser policy (--disable-webgl flag or Group Policy) where operationally feasible. Linux distributions including Debian, Fedora, and openSUSE have also released updated Chromium packages.
The update was covered by multiple security news outlets including Heise, GBHackers, CyberSecurityNews, PCWorld, and SecurityOnline, all highlighting the significance of the 26-vulnerability patch batch including three Critical-rated flaws (Heise, GBHackers). Researcher Catalin Cimpanu (@campuscodi) noted the vulnerability on Mastodon, drawing community attention to the exploit development activity observed at the BreakGlass Intel open directory (Mastodon). The Hacker News included the Chrome update in its weekly security recap, underscoring its broad relevance to the security community (The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."