Description
Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-03-11
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds read vulnerability was found within the Web Speech component of Google Chrome. The flaw allows a remote attacker to deliver a specially crafted web page that can trigger an out‑of‑bounds read and potentially escape the browser sandbox, providing an avenue for arbitrary code execution. The weakness is listed as CWE‑125, indicating unsafe memory handling.

Affected Systems

The flaw affects Google Chrome on all platforms that support Web Speech, including Windows, macOS, and Linux distributions. Chrome versions prior to 146.0.7680.71 are vulnerable. No specific kernel or operating system versions are required for exploitation beyond the need for the Chrome browser.

Risk and Exploitability

Google Chrome carries a CVSS score of 9.6, classifying the vulnerability as Critical. The EPSS score of <1% shows a very low estimated probability of exploitation at the time of analysis, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a remote attacker sending a malicious HTML page to a user, who must view the page in an unprivileged Chrome instance. If exploited, the attacker could gain code execution privileges within the user's sandbox, threatening confidentiality, integrity, and potentially the entire system depending on the sandbox escape path.

Generated by OpenCVE AI on April 16, 2026 at 02:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 146.0.7680.71 or later
  • If an update is not immediately possible, disable the Web Speech feature by navigating to chrome://settings/content/speech and setting “Ask before using” to off or setting “No” to use speaker voice
  • Monitor browser update channels and apply any subsequent security patches as they become available

Generated by OpenCVE AI on April 16, 2026 at 02:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6164-1 chromium security update
History

Fri, 13 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 13 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Out of bounds read in Web Speech
References
Metrics threat_severity

None

threat_severity

Important


Thu, 12 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 11 Mar 2026 22:15:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-03-12T19:26:24.152Z

Reserved: 2026-03-11T05:54:08.667Z

Link: CVE-2026-3916

cve-icon Vulnrichment

Updated: 2026-03-12T19:25:58.540Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-11T22:16:33.987

Modified: 2026-03-13T15:43:05.787

Link: CVE-2026-3916

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-10T00:00:00Z

Links: CVE-2026-3916 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T03:00:09Z

Weaknesses