
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4459 is an out-of-bounds read and write vulnerability in the WebAudio component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153 and Microsoft Edge (Chromium-based). The vulnerability was reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on March 6, 2026, and publicly disclosed on March 18–20, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla).
The vulnerability is rooted in improper bounds checking within Chrome's WebAudio implementation, classified as CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write). An attacker can craft a malicious HTML page that triggers out-of-bounds memory access in the WebAudio subsystem, leading to heap corruption. Exploitation requires no privileges and no special configuration, but does require user interaction — specifically, a victim must visit the attacker-controlled page. The Chromium issue tracker references bug ID 490246422 for this vulnerability (Chrome Releases, Red Hat Bugzilla).
Successful exploitation can lead to heap corruption, potentially enabling arbitrary code execution or information disclosure on the victim's system. An attacker who achieves code execution within the Chrome renderer process could further attempt sandbox escapes or lateral movement within the victim's environment. All three security dimensions — confidentiality, integrity, and availability — are rated High, reflecting the potential for full compromise of the affected browser session and underlying system data (Chrome Releases).
cmd.exe, powershell.exe, bash, curl) that are not typical browser behavior.Google has released Chrome 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac) to address this vulnerability; users should update immediately via Chrome's built-in update mechanism or by downloading from the official Chrome website. Microsoft Edge users should apply the corresponding Chromium-based Edge update from Microsoft. Linux distribution users (Debian, openSUSE, Fedora) should apply the Chromium package updates provided by their respective distribution security teams. No configuration-based workaround is available; patching is the only effective remediation (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome security update fixing 26 flaws, which received broad coverage from security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress, all highlighting the scale of the release and the risk of remote code execution (GBHackers, CyberSecurityNews). Palo Alto Networks also issued a security advisory (PAN-SA-2026-0007) referencing the affected Chromium codebase. Community reaction on platforms such as Mastodon noted the breadth of the update, with security professionals urging prompt patching given the High severity ratings across multiple components.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."