
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4462 is an out-of-bounds read vulnerability in the Blink rendering engine of Google Chrome that allows a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by security researcher heapracer (@heapracer) on March 9, 2026, and publicly disclosed on March 18, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) and is rated High severity by the Chromium security team (Chrome Releases, Red Hat Bugzilla, Microsoft MSRC).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in the Blink rendering engine, Chrome's HTML/CSS rendering component. An attacker can exploit this flaw by crafting a malicious HTML page that triggers an out-of-bounds memory read when processed by Blink, potentially exposing sensitive data from the browser's process memory. Exploitation requires user interaction — specifically, a victim must visit or be redirected to the attacker-controlled page — but no authentication or elevated privileges are required on the attacker's side. The Chromium issue tracker references bug ID 491080830 for this vulnerability (Chrome Releases, Red Hat Bugzilla).
Successful exploitation can result in high confidentiality, integrity, and availability impact, as reflected in the CVSS score. An attacker who lures a victim to a malicious webpage could read sensitive data from Chrome's process memory, potentially exposing credentials, session tokens, or other confidential information. In combination with other vulnerabilities, this out-of-bounds read could serve as a stepping stone toward more severe exploitation such as remote code execution (Chrome Releases, Red Hat Bugzilla).
Google has released a fix in Chrome stable channel version 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac); users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft has also released a corresponding update for Edge (Chromium-based), available through the Microsoft Security Response Center. As an interim measure, organizations should advise users to avoid visiting untrusted or suspicious websites and consider deploying content security policies. No configuration-based workaround is available that fully mitigates the vulnerability without patching (Chrome Releases, Microsoft MSRC).
The March 18, 2026 Chrome stable update, which addressed 26 security vulnerabilities including CVE-2026-4462, received broad coverage from security news outlets including GBHackers, CyberSecurityNews, and CyberNoz, with several articles highlighting the severity of the update and urging immediate user action. Red Hat tracked the vulnerability via its Bugzilla system and the OpenSUSE and Fedora communities issued downstream Chromium security advisories. Palo Alto Networks also published a security advisory (PAN-SA-2026-0007) referencing the affected Chromium codebase. Social media commentary was moderate, with security community accounts on Mastodon noting the update (Chrome Releases, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."