
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4458 is a use-after-free vulnerability in the Extensions component of Google Chrome that allows an attacker who convinces a user to install a malicious extension to potentially exploit heap corruption. It affects Google Chrome versions prior to 146.0.7680.153 and Microsoft Edge (Chromium-based). The vulnerability was reported by Shaheen Fazim on March 4, 2026, and publicly disclosed on March 18–20, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), occurring within Chrome's Extensions subsystem. A use-after-free condition arises when memory that has been freed is subsequently accessed, enabling an attacker to corrupt heap memory through a specially crafted Chrome Extension. Exploitation requires user interaction — specifically, convincing the target to install a malicious extension — but requires no special privileges on the attacker's part. The Chromium issue tracker references bug ID 489619753 for this vulnerability (Chrome Releases, Red Hat Bugzilla).
Successful exploitation of CVE-2026-4458 can lead to heap corruption, which may result in arbitrary code execution on the affected system. The CVSS assessment indicates high impact to confidentiality, integrity, and availability, meaning an attacker could potentially read sensitive data, modify system state, or cause a denial of service. Because the attack vector is network-based and requires only user interaction (not elevated privileges), the practical risk to end users who install extensions from untrusted sources is significant (Chrome Releases).
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ on Windows) with unfamiliar extension IDs.Google has released a patch in Chrome stable channel version 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac), which addresses this vulnerability along with 25 other security fixes. Microsoft has also issued guidance for Edge (Chromium-based) users. Users and administrators should update Chrome immediately via the browser's built-in update mechanism. As a supplementary measure, organizations should enforce policies restricting extension installation to approved sources only, and educate users about the risks of installing extensions from untrusted third-party sites (Chrome Releases, Microsoft).
The Chrome stable channel update fixing 26 vulnerabilities, including CVE-2026-4458, received broad coverage from security news outlets including GBHackers, CyberSecurityNews, CyberPress, and HealSecurity, with most articles emphasizing the severity of the batch update and urging immediate user action. The update was also noted in Linux distribution security advisories (Debian, openSUSE, Fedora) and picked up by Palo Alto Networks in a product security advisory. Social media discussion was moderate, with mentions on Mastodon via TheHackerWire. No major researcher controversy or vendor disputes were noted (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."