CVE-2026-4454 is a high-severity use-after-free vulnerability in the Network component of Google Chrome, affecting versions prior to 146.0.7680.153 across Apple, Google, Linux, and Microsoft platforms. Rated with a CVSS score of 8.8 (High), it allows a remote attacker to achieve heap corruption and potentially full compromise (C:H, I:H, A:H) with low attack complexity, requiring user interaction such as visiting a specially crafted HTML page. There is currently no evidence of active exploitation, it is not listed on CISA's KEV catalog, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB, with minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.153, < 146.0.7680.153CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.153CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.