
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4679 is an integer overflow vulnerability in the Fonts component of Google Chrome that allows a remote attacker to perform an out-of-bounds memory write via a crafted HTML page. It affects all versions of Google Chrome prior to 146.0.7680.165 (Windows/Mac) and 146.0.7680.164 (Linux), as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researchers GF and Un3xploitable of DeadSec on March 11, 2026, and publicly disclosed on March 23–24, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla).
The root cause is an integer overflow (CWE-190) in Chrome's Fonts subsystem, which can result in an out-of-bounds memory write — a condition where arithmetic on integer values wraps around, causing subsequent memory operations to target unintended memory regions. The attack vector is network-based and requires no special privileges; however, it does require user interaction, specifically a victim visiting a maliciously crafted HTML page that triggers the font processing code path. The Chromium issue tracker references bug ID 491516670 for this vulnerability, though full technical details remain restricted pending broad user update adoption (Chrome Releases, Red Hat Bugzilla).
Successful exploitation could allow a remote attacker to achieve arbitrary code execution or cause a denial of service within the Chrome renderer process, affecting confidentiality, integrity, and availability of the affected system. Because the out-of-bounds write occurs in the browser's font rendering pipeline, an attacker could potentially corrupt memory in ways that enable code execution under the browser's security context. While Chrome's sandbox provides some containment, a successful exploit could serve as a stepping stone for sandbox escape if chained with additional vulnerabilities (Chrome Releases).
Google has released a patched version of Chrome: 146.0.7680.164/165 for Windows and Mac, and 146.0.7680.164 for Linux. Users should update Chrome immediately by navigating to chrome://settings/help and applying any available update. Organizations should ensure automatic updates are enabled and consider using managed deployment tools (e.g., Google Admin Console, WSUS, or endpoint management platforms) to enforce the update across all endpoints. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update as tracked in the Microsoft Security Response Center (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a batch of 8 High-severity security fixes in Chrome 146, which received coverage from security-focused outlets including GBHackers, CyberSecurityNews, Forbes (Davey Winder), and WinBuzzer, highlighting the broad scope of the update affecting an estimated 3.5 billion Chrome users. Palo Alto Networks issued a Chromium monthly vulnerability update advisory (PAN-SA-2026-0004) covering this CVE. Linux distribution maintainers (Debian, Fedora, openSUSE, SUSE) also issued downstream advisories and updated their Chromium packages promptly (GBHackers, Palo Alto Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."