
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4442 is a heap buffer overflow vulnerability in the CSS parser of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects all versions of Google Chrome prior to 146.0.7680.153, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher Syn4pse on February 16, 2026, and publicly disclosed on March 18–20, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla, Microsoft MSRC).
The root cause is a heap-based buffer overflow (CWE-122) combined with incorrect calculation of buffer size (CWE-131) in Chrome's CSS parsing engine. An attacker can exploit this by serving a specially crafted HTML page containing malicious CSS that triggers the overflow when processed by the browser's CSS parser, leading to heap corruption. Exploitation requires user interaction — specifically, a victim must visit a malicious webpage — but no authentication or elevated privileges are needed on the attacker's side. The Chromium issue tracker references bug ID 484751092 for this vulnerability (Chrome Releases, Red Hat Bugzilla).
Successful exploitation can lead to arbitrary code execution on the affected system with the privileges of the user running Chrome, resulting in high impact to confidentiality, integrity, and availability. An attacker who achieves code execution within the browser process could potentially access sensitive user data, install malware, or use the compromised browser as a pivot point for further lateral movement within a network. The vulnerability affects all desktop platforms (Windows, macOS, Linux) running Chrome prior to 146.0.7680.153, as well as Chromium-based browsers such as Microsoft Edge (Chrome Releases, Microsoft MSRC).
cmd.exe, powershell.exe, bash, curl, wget); Chrome renderer crashes or unexpected restarts logged in system event logs.Google has released a patch in Chrome stable channel version 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac); users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge users should apply the corresponding Chromium-based Edge update from Microsoft. Organizations should ensure automatic updates are enabled for Chrome across all managed endpoints, and as an interim measure, web filtering or content inspection controls can be used to limit user exposure to untrusted or newly registered websites (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome security update addressing 26 vulnerabilities, which received broad coverage from cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, with headlines emphasizing the potential for remote code execution. Security community aggregators such as VulDB and infosec.exchange noted the release, and the update was tracked across Linux distribution security channels (Debian, Fedora, openSUSE) as Chromium packages were updated accordingly. No extraordinary researcher commentary or controversy specific to CVE-2026-4442 has been identified beyond standard patch notification coverage (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."