CVE-2026-4451 is a high-severity vulnerability in Google Chrome, affecting versions prior to 146.0.7680.153 and impacting products across Apple, Google, Linux, and Microsoft due to insufficient validation of untrusted input in the Navigation component. Rated 8.8 CVSS, this flaw allows a remote attacker, after compromising the renderer process, to achieve a sandbox escape via a crafted HTML page, leading to high confidentiality, integrity, and availability impacts. The attack requires user interaction but has low complexity. Currently, there is no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are presently very limited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.153, < 146.0.7680.153CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.153CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.