
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4444 is a stack buffer overflow vulnerability in the WebRTC component of Google Chrome that allows a remote attacker to potentially exploit stack corruption via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153 and Microsoft Edge (Chromium-based). The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on February 21, 2026, and patched on March 18, 2026, with Chrome's stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Advisory).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and CWE-120 (Buffer Copy without Checking Size of Input), residing in Chrome's WebRTC implementation. An attacker can exploit this flaw by crafting a malicious HTML page that triggers the overflow when processed by the WebRTC stack, leading to stack corruption. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but requires no special privileges or authentication. The Chromium issue tracker references bug ID 486349161 for this vulnerability (Chrome Releases, Red Hat Bugzilla).
Successful exploitation can result in high confidentiality, integrity, and availability impacts, potentially enabling remote code execution with the privileges of the Chrome browser process. An attacker who achieves code execution could access sensitive data within the browser context, install malware, or pivot to further compromise the underlying system. The vulnerability affects all major desktop platforms (Windows, macOS, Linux) running unpatched Chrome, as well as Chromium-based browsers such as Microsoft Edge (Red Hat Advisory, Chrome Releases).
RTCPeerConnection or related media negotiation functions) that bypasses bounds checking.chrome.exe / chrome) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, bash, curl, wget); abnormal memory usage spikes in the renderer process.Google has released Chrome version 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac) which addresses this vulnerability; users should update immediately (Chrome Releases). Microsoft has also released a corresponding update for Edge (Chromium-based) (Microsoft MSRC). Enabling automatic browser updates is the most effective mitigation. As a temporary measure, organizations can restrict access to untrusted websites via enterprise browser policies or deploy browser isolation technologies for high-risk users.
The patch was part of a large Chrome stable channel update fixing 26 security vulnerabilities, which received broad coverage from security news outlets including GBHackers, CyberSecurityNews, and CyberPress, highlighting the scale of the release and the potential for remote code execution (GBHackers, CyberSecurityNews). Security community discussion on Mastodon noted the significance of the update. Downstream Linux distributions including Debian, Fedora, and openSUSE issued their own Chromium security advisories in the days following the Chrome release.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."