Google disclosed three high-severity Chrome vulnerabilities affecting versions prior to 146.0.7680.165, including a use-after-free in FedCM (CVE-2026-4680), an integer overflow in the Fonts component (CVE-2026-4679), and a heap buffer overflow in WebGL (CVE-2026-4675). The bugs can be triggered through crafted HTML content and require user interaction, such as visiting a malicious page, with reported impacts including arbitrary code execution inside the browser sandbox, out-of-bounds memory writes, and out-of-bounds memory reads.
All three issues were assigned high-impact CVSS v3.1 ratings with the vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating network-reachable attack paths, low attack complexity, and potential compromise of confidentiality, integrity, and availability. The flaws map to memory-safety weaknesses including CWE-416, CWE-472, and CWE-122, and Google linked the advisories to Chrome stable channel updates and Chromium issue tracker entries as part of the fix rollout.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-24, a CVE record documented CVE-2026-4678, a high-severity use-after-free vulnerability in Chrome's WebGPU component affecting versions prior to 146.0.7680.165. Google said a remote attacker could execute arbitrary code inside the browser sandbox via a crafted HTML page, and the record included CWE-416, CVSS v3.1 details, and references added on the same day.
On 2026-03-24, a CVE record documented CVE-2026-4677, a high-severity out-of-bounds memory read vulnerability in Chrome's WebAudio component affecting versions prior to 146.0.7680.165. Google said a remote attacker could trigger the issue via a crafted HTML page, and the record included CWE-125, a high-impact CVSS v3.1 score, and references to Chrome release notes and the Chromium issue tracker.
Later on 2026-03-24, the CVE entries were updated to add CVSS v3.1 scoring, CWE classifications, and references to Chrome stable channel release notes and Chromium issue tracker entries. The updates further documented the potential for memory corruption and high impact to confidentiality, integrity, and availability.
On 2026-03-24, a CVE record documented CVE-2026-4676, a high-severity use-after-free vulnerability in Chrome's Dawn component affecting versions prior to 146.0.7680.165. Google said a remote attacker could potentially achieve a sandbox escape via a crafted HTML page.
On 2026-03-24, Google disclosed CVE-2026-4675, CVE-2026-4679, and CVE-2026-4680 affecting Chrome versions prior to 146.0.7680.165. The flaws impact WebGL, Fonts, and FedCM respectively, and all were rated high severity with crafted HTML pages as the attack vector.
On 2026-03-24, a CVE record documented CVE-2026-4674, a high-severity out-of-bounds read vulnerability in Chrome's CSS component affecting versions prior to 146.0.7680.165. Google said a remote attacker could trigger out-of-bounds memory access via a crafted HTML page, and the record included CWE-125, CVSS v3.1 details, and references to Chrome release notes and the Chromium issue tracker.
On 2026-03-23, Google announced a Stable channel update for Chrome Desktop, releasing version 146.0.7680.164/165 for Windows and Mac and 146.0.7680.164 for Linux. The rollout patched eight high-severity vulnerabilities across components including WebAudio, CSS, WebGL, Dawn, WebGPU, Fonts, and FedCM, with bug details restricted until users were broadly updated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
8 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcechromereleases.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.