CVE-2026-4460
vulnerability analysis and mitigation

Overview

CVE-2026-4460 is an out-of-bounds read vulnerability in the Skia graphics engine within Google Chrome that allows a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153 and Microsoft Edge (Chromium-based). The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 6, 2026, and publicly disclosed on March 18–20, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla, Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Skia, the open-source 2D graphics library used by Chrome for rendering. An attacker can exploit this by crafting a malicious HTML page that triggers improper memory access within the Skia rendering pipeline, causing the browser to read memory outside the bounds of an allocated buffer. Exploitation requires no special privileges but does require user interaction — specifically, a victim visiting or being redirected to a malicious web page. The Chromium issue tracker references bug ID 490254124 for this vulnerability (Chrome Releases, Red Hat Bugzilla).

Impact

Successful exploitation can result in high confidentiality, integrity, and availability impact on the affected system, as reflected in the CVSS scoring. An attacker could read sensitive memory contents from the Chrome renderer process, potentially exposing credentials, session tokens, or other in-memory data. In more severe scenarios, the out-of-bounds read could be chained with other vulnerabilities to achieve code execution within the browser's renderer sandbox, potentially enabling further lateral movement or sandbox escape (Chrome Releases, Red Hat Bugzilla).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 146.0.7680.153 or unpatched Microsoft Edge (Chromium-based) using browser fingerprinting techniques or social engineering.
  2. Craft malicious HTML page: Develop a specially crafted HTML page that triggers abnormal rendering behavior in Chrome's Skia graphics engine, causing it to perform an out-of-bounds memory read (e.g., via malformed SVG, canvas, or CSS rendering operations).
  3. Deliver payload: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing email, malicious advertisement, or compromised website.
  4. Trigger out-of-bounds read: When the victim's browser renders the crafted page, the Skia engine reads memory outside the intended buffer boundary, potentially leaking sensitive in-memory data to the attacker.
  5. Leverage leaked data or chain exploits: Use the disclosed memory contents (e.g., heap addresses, credentials) to bypass ASLR or chain with additional vulnerabilities for sandbox escape or remote code execution (Chrome Releases).

Indicators of compromise

  • Network: Unusual outbound connections from the browser process to unknown external IPs following visits to unfamiliar or suspicious websites; HTTP/HTTPS requests to newly registered or low-reputation domains serving complex HTML/SVG/canvas content.
  • Process: Chrome renderer processes (chrome.exe / chrome subprocess) exhibiting abnormal memory usage or crashing unexpectedly; unexpected child processes spawned from the browser renderer.
  • Logs: Browser crash reports or dump files referencing Skia rendering components; application event log entries indicating renderer process termination or sandbox violations.
  • File System: Unexpected files written to the user's temp directory or Chrome profile directory following browser crashes, which may indicate exploit staging artifacts.

Mitigation and workarounds

Google has released a fix in Chrome stable channel version 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac). Microsoft has also issued a corresponding update for Edge (Chromium-based). Users and organizations should immediately update Chrome and Edge to the latest available versions. As a temporary workaround prior to patching, organizations can restrict access to untrusted or external websites via web proxy policies and enforce browser update policies to block older versions from accessing internal resources (Chrome Releases, Microsoft MSRC).

Community reactions

The vulnerability was part of a broader Chrome stable channel update that patched 26 security issues, including three Critical-rated CVEs, which drew significant coverage from security news outlets. Publications such as GBHackers, CyberSecurityNews, and CyberPress reported on the update, highlighting the high number of fixes and the potential for remote code execution across the vulnerability set. The update was also picked up by Linux distribution security advisories (Debian, openSUSE, Fedora) and scanner vendors (Tenable Nessus, Qualys), reflecting broad industry attention to the release (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management