CVE-2026-4446: Use after free in WebRTC
Chromium: CVE-2026-4446 Use after free in WebRTC
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-4446?
CVE-2026-4446 has a high severity rating due to potential heap corruption vulnerabilities in WebRTC.
How do I fix CVE-2026-4446?
To fix CVE-2026-4446, update Google Chrome to version 146.0.7680.153 or later.
What impact can CVE-2026-4446 have on users?
CVE-2026-4446 could allow remote attackers to exploit vulnerabilities via crafted HTML pages, potentially compromising user systems.
Which versions of Google Chrome are affected by CVE-2026-4446?
CVE-2026-4446 affects all versions of Google Chrome prior to 146.0.7680.153.
Is CVE-2026-4446 related to WebRTC?
Yes, CVE-2026-4446 is specifically a use after free vulnerability in the WebRTC component of Google Chrome.