
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4676 is a use-after-free vulnerability in the Dawn graphics component of Google Chrome that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.164/165 and Microsoft Edge (Chromium-based). The vulnerability was reported on March 1, 2026, and publicly disclosed on March 23–24, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Chrome's Dawn component — the WebGPU implementation layer. When a specially crafted HTML page triggers certain GPU-related operations in Dawn, a dangling pointer to freed memory can be dereferenced, potentially allowing an attacker to corrupt memory and escape the Chrome sandbox. Exploitation requires user interaction, specifically visiting a malicious webpage, but no authentication or elevated privileges are needed. The bug was tracked internally as Chromium issue 488613135 and reported by researcher 86ac1f1587b71893ed2ad792cd7dde32 (Chrome Releases).
Successful exploitation could allow a remote attacker to escape Chrome's sandbox and achieve remote code execution on the underlying host system. The vulnerability carries high confidentiality, integrity, and availability impacts, meaning an attacker could steal sensitive data, modify system content, or cause denial of service. Given the sandbox escape potential, exploitation could enable lateral movement or installation of persistent malware beyond the browser process (Chrome Releases).
Google has released a fix in Chrome stable channel version 146.0.7680.164 (Linux) and 146.0.7680.164/165 (Windows/Mac). Users should immediately update Chrome to this version or later. Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory. Enabling automatic updates in Chrome is the recommended approach to ensure timely patching. As a temporary measure, organizations should restrict access to untrusted or unknown websites and educate users about the risks of visiting unverified pages (Chrome Releases, Microsoft MSRC).
The vulnerability received broad coverage from security media outlets including GBHackers, CyberSecurityNews, Forbes, and WinBuzzer, which highlighted it as part of a batch of 8 high-severity Chrome vulnerabilities patched in the March 23, 2026 update (GBHackers, Forbes). The Hacker Wire published a dedicated technical article on the Dawn use-after-free sandbox escape (The Hacker Wire). Community discussion on Mastodon and Bluesky noted the sandbox escape potential as particularly concerning. Downstream Linux distributions including Debian, Fedora, and openSUSE issued their own Chromium security advisories shortly after Google's disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."