Description
Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-03-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential remote heap corruption leading to code execution or data corruption
Action: Immediate Patch
AI Analysis

Impact

Out of bounds write in the V8 JavaScript engine can corrupt heap objects when processing a crafted HTML page. This flaw allows a remote attacker to cause memory corruption, potentially leading to arbitrary code execution or denial of service. The weakness is identified as a buffer overread and write, consistent with a covariance in memory management (CWE-787).

Affected Systems

The vulnerability affects Google Chrome across all operating systems where Chrome is available – Windows, macOS, and Linux. Versions of Chrome prior to 146.0.7680.153 are impacted; installing any newer release mitigates the problem.

Risk and Exploitability

The vulnerability carries a high severity CVSS score of 8.8 and has a very low EPSS score (<1%), indicating that widespread exploitation is not expected yet. It is not listed in the CISA KEV catalog. Attackers are able to trigger the exploit by delivering a malicious HTML page to a vulnerable browser, either through the Internet or local file inclusion, making the attack vector remote and web-based. Given the nature of the flaw, successful exploitation can compromise confidentiality, integrity, and availability of the affected system.

Generated by OpenCVE AI on March 20, 2026 at 19:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 146.0.7680.153 or later.

Generated by OpenCVE AI on March 20, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6171-1 chromium security update
History

Fri, 20 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 20 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 20 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in V8 Leading to Heap Corruption in Google Chrome chromium-browser: Out of bounds write in V8
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Fri, 20 Mar 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in V8 Leading to Heap Corruption in Google Chrome

Fri, 20 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 20 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
Description Out of bounds write in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-03-21T04:01:16.425Z

Reserved: 2026-03-19T20:23:50.820Z

Link: CVE-2026-4450

cve-icon Vulnrichment

Updated: 2026-03-20T14:34:41.876Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-20T02:16:37.917

Modified: 2026-03-20T18:05:22.007

Link: CVE-2026-4450

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-18T00:00:00Z

Links: CVE-2026-4450 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:09:55Z

Weaknesses