CVE-2026-4680
HIGH
apple, google, linux, microsoft
NVD
CVSS Score
8.8
Severity
HIGH
Published
Mar 24, 2026
Vendor
apple, google, linux, microsoft
Description
Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)