
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4464 is an integer overflow vulnerability in the ANGLE (Almost Native Graphics Layer Engine) graphics library in Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.153 and Microsoft Edge (Chromium-based). The vulnerability was reported by researcher "heesun" on 2026-02-24 and publicly disclosed on 2026-03-18 when Google released Chrome 146.0.7680.153/154. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release Blog, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) in Chrome's ANGLE graphics abstraction layer, which translates OpenGL ES API calls to platform-specific graphics APIs (DirectX, OpenGL, Vulkan). When processing a specially crafted HTML page containing malicious graphics content, an arithmetic operation on an integer value overflows, leading to heap corruption. This class of bug can result in out-of-bounds memory writes, enabling an attacker to corrupt heap metadata or overwrite adjacent memory regions. Exploitation requires user interaction — specifically, a victim visiting a malicious or compromised web page — but requires no special privileges from the attacker (Chrome Release Blog, Red Hat Bugzilla).
Successful exploitation could allow a remote attacker to achieve arbitrary code execution within the Chrome renderer process, with potential for sandbox escape leading to full system compromise. The vulnerability affects confidentiality, integrity, and availability at a high level, as heap corruption primitives can be leveraged to control program execution flow. Affected assets include any system running a vulnerable version of Google Chrome or Chromium-based browsers (including Microsoft Edge) across Windows, macOS, and Linux platforms (Chrome Release Blog, Microsoft MSRC).
chrome.exe, chromium-browser) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, sh, bash) or making unusual system calls.Google has released a patched version of Chrome (146.0.7680.153 for Linux, 146.0.7680.153/154 for Windows/Mac) that addresses this vulnerability. Users and organizations should immediately update Google Chrome to version 146.0.7680.153 or later. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update. As a temporary measure, organizations can implement web content filtering to block access to untrusted or suspicious websites while patches are being deployed. Enabling Chrome's automatic update mechanism ensures timely patching (Chrome Release Blog, Microsoft MSRC).
The vulnerability was part of a broader Chrome security update that patched 26 vulnerabilities, including three Critical-rated issues, which drew significant coverage from security news outlets including GBHackers, CyberSecurityNews, and CyberPress. Coverage highlighted the overall update as a major security release, with multiple outlets urging immediate user action. Palo Alto Networks also issued a security advisory (PAN-SA-2026-0004) addressing Chromium-based vulnerabilities in their products. Linux distribution maintainers (Debian, openSUSE, Fedora) issued downstream advisories and package updates for Chromium (Chrome Release Blog, Palo Alto Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."