
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4680 is a use-after-free vulnerability in the Federated Credential Management (FedCM) component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported by security researcher Shaheen Fazim on March 12, 2026, and publicly disclosed on March 23, 2026, when Google released Chrome 146.0.7680.164/165 to address the issue (Chrome Releases). The vulnerability affects all Google Chrome versions prior to 146.0.7680.164/165, as well as Microsoft Edge (Chromium-based) (Red Hat Bugzilla, Microsoft MSRC). It carries a CVSS v3.1 base score of 8.8 (High), reflecting network-based exploitation requiring user interaction but no privileges (Chrome Releases).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Chrome's FedCM implementation — the browser API that facilitates federated identity flows (Red Hat Bugzilla). An attacker can trigger the use-after-free condition by crafting a malicious HTML page that manipulates FedCM's object lifecycle, causing the browser to access memory that has already been freed. Exploitation requires the victim to visit the attacker-controlled page (user interaction required), but no authentication or special privileges are needed on the attacker's side. The bug was tracked internally as Chromium issue 491869946 and was part of a broader set of 8 high-severity memory safety fixes in the same Chrome release (Chrome Releases).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, resulting in high confidentiality, integrity, and availability impact on the affected browser process. While the sandbox limits direct access to the underlying operating system, code execution within the sandbox can serve as a stepping stone for sandbox escape chains when combined with additional vulnerabilities. Affected users across all platforms (Windows, macOS, Linux) running Chrome prior to 146.0.7680.164/165 are at risk, as are users of Chromium-based browsers such as Microsoft Edge (Chrome Releases, Microsoft MSRC).
chrome://crashes) associated with FedCM-related stack traces.Google has released Chrome 146.0.7680.164 (Linux) and 146.0.7680.165 (Windows/Mac) which contain the fix; users should update immediately via Chrome's built-in update mechanism (chrome://settings/help) (Chrome Releases). Microsoft has also issued guidance for Edge (Chromium-based) users through the Microsoft Security Response Center (Microsoft MSRC). Organizations should enable automatic browser updates and verify deployment via endpoint management tools. As a temporary measure prior to patching, users should avoid visiting untrusted websites and consider disabling or restricting access to sites using FedCM-based identity flows.
The vulnerability was covered by several security-focused outlets including GBHackers, CyberSecurityNews, and Forbes, which highlighted the broader Chrome 146 update fixing 8 high-severity vulnerabilities (GBHackers, Forbes). The Hacker Wire published a dedicated technical write-up on CVE-2026-4680 focusing on the FedCM use-after-free leading to sandbox arbitrary code execution (The Hacker Wire). Community discussion on Mastodon and Bluesky noted the patch but did not indicate widespread alarm given the absence of active exploitation. Palo Alto Networks also issued a Chromium monthly vulnerability update advisory (PAN-SA-2026-0004) covering this CVE for their affected products (Palo Alto).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."