CVE-2026-4674 is a high-severity out-of-bounds read vulnerability in Google Chrome, affecting versions prior to 146.0.7680.165 across Apple, Google, Linux, and Microsoft platforms. Rated 8.8 HIGH on CVSS, it allows a remote attacker to achieve high confidentiality, integrity, and availability impacts by enticing a user to visit a specially crafted HTML page. The attack requires user interaction but has low attack complexity. There is currently no evidence of active exploitation or public exploit code, though it has received some community discussion and media coverage regarding security updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.165, < 146.0.7680.165CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.164CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.