
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4443 is a heap buffer overflow vulnerability in the WebAudio component of Google Chrome that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153 and Microsoft Edge (Chromium-based). The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on February 18, 2026, and publicly disclosed on March 18, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Advisory).
The root cause is a heap-based buffer overflow (CWE-122) in Chrome's WebAudio implementation, where insufficient bounds checking during audio processing allows memory corruption via a specially crafted HTML page. An attacker can exploit this by hosting or distributing a malicious webpage that triggers the overflow when processed by the WebAudio API, resulting in arbitrary code execution within the browser's sandbox. Exploitation requires no privileges and no special configuration — only that the victim visits the attacker-controlled page (user interaction required). The Chromium issue tracker references bug ID 485292589 for this vulnerability (Chrome Releases, Red Hat Bugzilla).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, potentially compromising confidentiality, integrity, and availability of data processed by the browser. While sandbox containment limits direct host OS access, a sandbox escape chained with this vulnerability could lead to full system compromise. Affected users risk exposure of browser-stored credentials, session tokens, and sensitive data rendered within the browser context (Red Hat Advisory, Chrome Releases).
chrome.exe or chromium (e.g., cmd.exe, powershell.exe, bash, curl) that are inconsistent with normal browser behavior; renderer process crashes or unexpected restarts.Google has released a patched version of Chrome — 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac) — which addresses this vulnerability. Users should update Chrome immediately via Settings > Help > About Google Chrome, or enable automatic updates. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update. Organizations should enforce automatic browser updates via policy and consider restricting access to untrusted or unknown websites using web filtering solutions (Chrome Releases, Microsoft).
The vulnerability was part of a larger Chrome stable channel update that patched 26 security issues, drawing coverage from multiple cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, which highlighted the batch of remote code execution-capable flaws. The update was also noted by Linux distribution security teams, with Debian, Fedora, and openSUSE issuing Chromium package updates shortly after Google's release. No notable individual researcher commentary or significant social media controversy was observed beyond standard patch reporting (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."