CVE-2026-4680 is a high-severity use-after-free vulnerability in the FedCM component of Google Chrome, affecting versions prior to 146.0.7680.165 and potentially other Chromium-based browsers across Apple, Google, Linux, and Microsoft platforms. This flaw carries a CVSS score of 8.8, indicating a critical risk where a remote attacker could execute arbitrary code inside the browser's sandbox. The attack vector is via the network with low complexity, but it requires user interaction, typically by visiting a crafted HTML page. Currently, there is no evidence of active exploitation, the vulnerability is not listed in CISA's KEV catalog, and no public exploit code is available. Community discussion and media coverage remain low, primarily revolving around vendor security updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.165, < 146.0.7680.165CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.164CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.