
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4457 is a Type Confusion vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153 and Microsoft Edge (Chromium-based). The vulnerability was reported by Zhenpeng (Leo) Lin at depthfirst on March 1, 2026, and Google disclosed and patched it on March 18, 2026 with the Chrome 146.0.7680.153 stable channel release. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla, Microsoft MSRC).
The root cause is a Type Confusion flaw (CWE-843: Access of Resource Using Incompatible Type) in Chrome's V8 JavaScript engine, where the engine incorrectly handles object types during JavaScript execution, leading to heap corruption. An attacker can exploit this by crafting a malicious HTML page that triggers the type confusion condition when parsed and executed by V8. The attack vector is network-based, requires no privileges, but does require user interaction (visiting a malicious page). The vulnerability is tracked under Chromium issue 488803413 (Chrome Releases, Red Hat Bugzilla).
Successful exploitation could allow a remote attacker to achieve arbitrary code execution within Chrome's renderer process context through heap corruption, with potential impacts to confidentiality, integrity, and availability all rated High. An attacker who successfully exploits this vulnerability could read sensitive data from memory, corrupt process state, or potentially escape the browser sandbox with additional exploit chaining. The vulnerability affects all platforms (Windows, macOS, Linux) running Chrome prior to 146.0.7680.153, as well as Microsoft Edge Chromium-based builds (Chrome Releases, Microsoft MSRC).
chrome.exe / chrome on Linux/macOS) spawning unexpected child processes such as command shells (cmd.exe, /bin/bash) or network utilities (curl, wget, powershell).Google has released Chrome 146.0.7680.153 (Linux) / 146.0.7680.153/154 (Windows/Mac) which addresses this vulnerability; users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome) (Chrome Releases). Microsoft has also released a corresponding update for Edge Chromium (Microsoft MSRC). Organizations should enforce automatic Chrome/Edge updates across all endpoints and, until patching is complete, educate users to avoid visiting untrusted or unfamiliar websites. Linux distributions including Debian, Fedora, and openSUSE have also released updated Chromium packages addressing this vulnerability.
The vulnerability was part of a larger Chrome 146 security update that fixed 26 total vulnerabilities, including three Critical-rated flaws, which drew significant media attention. Security outlets including GBHackers, CyberSecurityNews, PCWorld, and CyberPress covered the update, emphasizing the breadth of the patch and urging immediate user action (GBHackers, PCWorld). Palo Alto Networks also issued a security advisory (PAN-SA-2026-0007) referencing this CVE in the context of their Chromium-based products (Palo Alto Advisory). Community reaction was generally focused on the scale of the update rather than this specific CVE, as no active exploitation was reported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."