Description
Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-03-20
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential heap corruption
Action: Patch ASAP
AI Analysis

Impact

An integer overflow occurs in the ANGLE graphics layer of Google Chrome, allowing a maliciously crafted HTML page to corrupt heap objects. This flaw, reflected in the CWE‑190 and CWE‑472 identifiers, can lead to integrity violations within the browser process. The description explicitly states that the vulnerability can cause heap corruption, but it does not confirm execution of arbitrary code, so the impact is limited to corruption of internal data structures.

Affected Systems

All users who have Google Chrome versions earlier than 146.0.7680.153 on Windows, macOS, and Linux are affected. The flaw applies to any stable channel installation of Chrome that predates the March 2026 update released by Google.

Risk and Exploitability

The CVSS score of 8.8 marks this as high severity, while the EPSS score of less than 1% indicates a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack is most likely carried out through a remote browser interaction with a crafted HTML page; this inference is drawn from the description that the flaw can be triggered via a crafted page.

Generated by OpenCVE AI on March 20, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 146.0.7680.153 or later

Generated by OpenCVE AI on March 20, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6171-1 chromium security update
History

Fri, 20 Mar 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 20 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 20 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in ANGLE Causes Potential Heap Corruption in Google Chrome chromium-browser: Integer overflow in ANGLE
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Moderate


Fri, 20 Mar 2026 11:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in ANGLE Causes Potential Heap Corruption in Google Chrome

Fri, 20 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 20 Mar 2026 02:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-03-21T04:01:05.873Z

Reserved: 2026-03-19T20:23:56.088Z

Link: CVE-2026-4464

cve-icon Vulnrichment

Updated: 2026-03-20T14:15:38.491Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-20T02:16:39.907

Modified: 2026-03-20T17:56:05.140

Link: CVE-2026-4464

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-03-18T00:00:00Z

Links: CVE-2026-4464 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:09:42Z

Weaknesses