Description
Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-03-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free bug in Blink, the rendering engine of Google Chrome, allows a heap corruption condition to be triggered by a crafted HTML page. The vulnerability is rated high severity and can lead to arbitrary code execution if successfully exploited.

Affected Systems

Users running Google Chrome versions prior to 146.0.7680.153 on any operating system, including Windows, macOS, and Linux, are affected. The issue does not affect other browsers or Chrome extensions directly.

Risk and Exploitability

The CVSS score of 8.8 indicates a substantial risk, and the EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is a remote attacker delivering malicious HTML content that triggers the use‑after‑free while the browser is rendering the page, compromising the browser process and potentially the system.

Generated by OpenCVE AI on March 20, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (146.0.7680.153 or newer).
  • Restart Chrome after the update to ensure the patch is loaded.
  • Keep the operating system and any browser extensions up to date to reduce ancillary risk.

Generated by OpenCVE AI on March 20, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6171-1 chromium security update
History

Fri, 20 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 20 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 20 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Blink Leading to Potential Heap Corruption in Chrome chromium-browser: Use after free in Blink
Weaknesses CWE-1341
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Fri, 20 Mar 2026 11:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Blink Leading to Potential Heap Corruption in Chrome

Fri, 20 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 20 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
Description Use after free in Blink in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-03-21T04:01:17.525Z

Reserved: 2026-03-19T20:23:50.609Z

Link: CVE-2026-4449

cve-icon Vulnrichment

Updated: 2026-03-20T14:34:44.920Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-20T02:16:37.773

Modified: 2026-03-20T18:04:51.990

Link: CVE-2026-4449

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-18T00:00:00Z

Links: CVE-2026-4449 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:09:56Z

Weaknesses