CVE-2026-4679: High Integer overflow in Fonts
Chromium: CVE-2026-4679 Integer overflow in Fonts
Other sources
Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-5291
- CVE-2026-4449
- CVE-2026-4674
- CVE-2026-4442
- CVE-2026-4451
- CVE-2026-5292
- CVE-2026-5282
- CVE-2026-3922
- CVE-2026-5280
- CVE-2026-4458
- CVE-2026-3923
- CVE-2026-4462
- CVE-2026-4454
- CVE-2026-4675
- CVE-2025-37752
- CVE-2025-37756
- CVE-2025-37797
- CVE-2025-37890
- CVE-2025-37997
- CVE-2025-38000
- CVE-2025-38001
- CVE-2025-38083
- CVE-2025-38177
- CVE-2025-38350
- CVE-2025-38477
- CVE-2025-38616
- CVE-2025-38617
- CVE-2025-38618
Frequently Asked Questions
What is the severity of CVE-2026-4679?
CVE-2026-4679 has a high severity rating due to its potential for remote exploitation.
How do I fix CVE-2026-4679?
To fix CVE-2026-4679, update Google Chrome to version 146.0.7680.165 or later.
What impact does CVE-2026-4679 have on my system?
CVE-2026-4679 allows a remote attacker to perform out of bounds memory writes, which could lead to arbitrary code execution.
Which versions of Google Chrome are affected by CVE-2026-4679?
CVE-2026-4679 affects all versions of Google Chrome prior to 146.0.7680.165.
Are there any workarounds for CVE-2026-4679?
There are no known workarounds for CVE-2026-4679; the best course of action is to apply the latest update.