CVE-2026-4459 is a high-severity out-of-bounds read and write vulnerability in Google Chrome's WebAudio component, affecting versions prior to 146.0.7680.153 across various operating systems. Rated 8.8 HIGH, this flaw allows a remote attacker to exploit heap corruption with low complexity via a crafted HTML page, potentially leading to significant system compromise. Although user interaction is required, there is currently no evidence of active exploitation, nor are public exploit modules available. Community discussion and media coverage remain low, suggesting limited public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.153, < 146.0.7680.153CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.153CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.