
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4453 is an integer overflow vulnerability in the Dawn graphics component of Google Chrome on macOS that allows a remote attacker to leak cross-origin data via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153 on Mac, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher "sweetchip" on February 27, 2026, and publicly disclosed on March 18–20, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated High severity by Chromium's internal security team (Chrome Releases, Red Hat Bugzilla).
The root cause is an integer overflow (CWE-190) in Dawn, the cross-platform GPU graphics abstraction layer used by Chrome on macOS. When processing a specially crafted HTML page, the overflow condition in Dawn's graphics pipeline can be triggered remotely, causing the browser to read memory beyond intended boundaries and expose data from cross-origin contexts — a violation of the same-origin policy. The attack requires no privileges and no special configuration, but does require user interaction (visiting a malicious page). The vulnerability is tracked under Chromium issue 488400770 (Chrome Releases, Red Hat Bugzilla).
Successful exploitation allows a remote attacker to bypass the browser's same-origin policy and leak sensitive cross-origin data, potentially exposing session tokens, authentication cookies, or other private information from websites open in the same browser context. The impact is limited to confidentiality — there is no integrity or availability impact — and is scoped to macOS users running affected Chrome versions. While not a full remote code execution vulnerability, the data exfiltration capability poses a meaningful risk for users accessing sensitive web applications (Chrome Releases).
chrome://crashes).Google Chrome Helper (GPU)) consuming abnormal memory or CPU on macOS; renderer process crashes associated with graphics operations.~/Library/Caches/Google/Chrome/).Google has released a fix in Chrome stable channel version 146.0.7680.153 (Linux/Mac) and 146.0.7680.153/154 (Windows). Users should update Chrome immediately via Settings > Help > About Google Chrome or enable automatic updates. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a temporary workaround, macOS users can disable WebGPU via Chrome flags (chrome://flags/#enable-unsafe-webgpu) or restrict access to untrusted websites until patching is complete (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a broader Chrome stable channel update that patched 26 security issues, drawing coverage from multiple cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, which highlighted the update's significance given the number of high-severity fixes. Security community attention was moderate, consistent with a data-leakage vulnerability rather than a remote code execution flaw. No notable individual researcher commentary beyond the original reporter (sweetchip) has been identified (GBHackers, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."