
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4677 is an out-of-bounds read vulnerability in the WebAudio component of Google Chrome that allows a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. The vulnerability was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on March 7, 2026, and publicly disclosed on March 23–24, 2026, as part of a Chrome stable channel update addressing 8 security fixes. It affects all versions of Google Chrome prior to 146.0.7680.164/165, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla, Microsoft MSRC).
The root cause is classified as CWE-125 (Out-of-bounds Read), stemming from an inappropriate implementation in Chrome's WebAudio subsystem. An attacker can exploit this by serving a specially crafted HTML page that triggers the WebAudio engine to read memory beyond the bounds of an allocated buffer. Exploitation requires user interaction — specifically, a victim visiting a malicious or attacker-controlled webpage — but requires no special privileges or authentication. The Chromium issue tracker references bug ID 490533968, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, Red Hat Bugzilla).
Successful exploitation could allow a remote attacker to read sensitive out-of-bounds memory contents from the Chrome renderer process, potentially exposing authentication tokens, cryptographic keys, or other sensitive data processed by the browser. The CVSS scoring reflects high impact across confidentiality, integrity, and availability, suggesting the out-of-bounds read could be chained with other vulnerabilities to achieve more severe outcomes such as code execution or sandbox escape. All platforms running vulnerable Chrome versions (Windows, macOS, Linux) and Chromium-based browsers such as Microsoft Edge are affected (Chrome Releases, Microsoft MSRC).
chrome.exe / chrome subprocess) with memory-related error codes.Google has released the fix in Chrome stable channel version 146.0.7680.164 (Linux) and 146.0.7680.165 (Windows/Mac), released March 23, 2026. Microsoft has also released a corresponding update for Microsoft Edge (Chromium-based). Users and administrators should immediately update Chrome to version 146.0.7680.165 or later via the browser's built-in update mechanism or enterprise deployment tools. As an additional measure, organizations should consider implementing web content filtering to reduce exposure to malicious HTML pages, and ensure auto-update policies are enforced across all managed endpoints (Chrome Releases, Microsoft MSRC).
The vulnerability was covered by several security news outlets as part of broader reporting on the Chrome 146 update, which addressed 8 high-severity vulnerabilities. GBHackers and CyberSecurityNews published articles summarizing the update, and Forbes highlighted the patch as a high-risk security update for Chrome's 3.5 billion users. The Hacker News included the vulnerability in its weekly security recap. No significant controversy or researcher debate has been noted beyond standard patch advisory coverage (GBHackers, Forbes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."