
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4454 is a use-after-free vulnerability in the Network component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects all versions of Google Chrome prior to 146.0.7680.153, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher heapracer (@heapracer) on March 1, 2026, and publicly disclosed on March 18–20, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Chrome's Network component. A use-after-free condition occurs when the browser accesses memory that has already been freed, allowing an attacker to potentially control the freed memory region and redirect execution flow. Exploitation requires no authentication or special privileges but does require user interaction — specifically, a victim visiting a malicious HTML page crafted to trigger the vulnerable code path. The Chromium issue tracker references bug ID 488585488 for this vulnerability (Chrome Releases, Red Hat Bugzilla).
Successful exploitation can result in heap corruption, which may lead to denial of service (browser crash), data corruption, or potentially remote code execution within the context of the browser process. An attacker who achieves code execution could access sensitive data processed by the browser, including credentials, session tokens, and browsing history. While the vulnerability is sandboxed within the browser, a successful exploit could serve as a stepping stone for sandbox escape if chained with additional vulnerabilities (Chrome Releases, Red Hat Bugzilla).
cmd.exe, powershell.exe, bash) or crashing repeatedly with heap-related errors.%LOCALAPPDATA%\Google\Chrome\User Data\Crashpad\reports\ on Windows).Google has released Chrome 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac) to address this vulnerability; users should update immediately via Chrome's built-in update mechanism or by downloading from the official Chrome website. Microsoft has also released a corresponding update for Edge (Chromium-based), tracked under the same CVE. As a temporary workaround where immediate patching is not feasible, organizations should restrict user access to untrusted or unknown websites and consider deploying browser isolation solutions. Linux distributions including Debian, Fedora, and openSUSE have also released updated Chromium packages (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a larger Chrome stable channel update that patched 26 security issues, which received broad coverage from security news outlets including GBHackers, CyberSecurityNews, CyberPress, and HealSecurity, with headlines emphasizing the potential for remote code execution. Security community members on Mastodon and Infosec.exchange noted the update's significance given the number of high-severity fixes included. Palo Alto Networks also issued a security advisory (PAN-SA-2026-0007) referencing this and related Chrome vulnerabilities affecting their products (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."