
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4678 is a use-after-free vulnerability in the WebGPU component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported internally by Google on March 10, 2026, and publicly disclosed on March 23, 2026, when Google released Chrome 146.0.7680.164/165. All versions of Google Chrome prior to 146.0.7680.164 (Linux) / 146.0.7680.165 (Windows/Mac) are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Advisory, Red Hat Bugzilla).
The root cause is a use-after-free memory corruption flaw (CWE-416 / CWE-825) in Chrome's WebGPU implementation. Use-after-free vulnerabilities occur when a program continues to use a pointer after the memory it references has been freed, potentially allowing an attacker to control the freed memory region and redirect execution flow. Exploitation requires user interaction — specifically, a victim visiting a malicious or attacker-controlled webpage containing a crafted HTML page that triggers the vulnerable WebGPU code path. The bug was tracked internally as Chromium issue 491164019 and was discovered by Google's own security team (Chrome Advisory, Red Hat Bugzilla).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, impacting confidentiality, integrity, and availability (all rated High in the CVSS assessment). While execution is constrained to the sandbox, this class of vulnerability is frequently chained with a sandbox escape to achieve full system compromise. All users running unpatched Chrome or Chromium-based browsers (including Microsoft Edge) across Windows, macOS, and Linux are at risk (Chrome Advisory).
GPUDevice, GPUBuffer, or GPUCommandEncoder) in a sequence that causes a dangling pointer dereference after object destruction.Google has released patched versions: Chrome 146.0.7680.165 for Windows/Mac and 146.0.7680.164 for Linux — users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge users should apply the corresponding Chromium-based Edge update via the Microsoft Security Response Center advisory. As a temporary workaround where patching is not immediately possible, restrict user access to untrusted or unknown websites, or consider disabling WebGPU functionality if the deployment environment supports it. Debian, Fedora, openSUSE, and FreeBSD have also released updated Chromium packages addressing this vulnerability (Chrome Advisory, Microsoft).
The vulnerability was covered by security-focused outlets including GBHackers, CyberSecurityNews, Forbes (Davey Winder), WinBuzzer, and BornCity, all noting the broader Chrome 146 update that addressed 8 high-severity vulnerabilities. Forbes highlighted the update as a "high-risk security update" for Chrome's 3.5 billion users. The security community on Mastodon (infosec.exchange) and Bluesky noted the CVE shortly after disclosure. No significant controversy or researcher-specific commentary beyond standard patch advisories was observed (GBHackers, Forbes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."