Security Advisory Desk
highQCS priority 94/100Microsoft

CVE-2026-4450: Chromium: CVE-2026-4450 Out of bounds write in V8

A security vulnerability named CVE-2026-4450 was found in the Chromium browser engine's V8 JavaScript component. This flaw allows an out-of-bounds write, meaning the software might write data outside of allowed memory areas, which can cause crashes or allow attackers to execute harmful code. Microsoft Edge, which is based on Chromium, includes this fix in its version 146.0.3856.72 and later. Users should update Edge to this version or newer to stay protected.

QCS published 4/10/2026, 5:36:48 am ISTVendor disclosure 10/3/2026, 12:30:00 pm ISTVerified 4/10/2026, 5:36:48 am ISTRevision 1

In plain language

What this advisory means

A security vulnerability named CVE-2026-4450 was found in the Chromium browser engine's V8 JavaScript component. This flaw allows an out-of-bounds write, meaning the software might write data outside of allowed memory areas, which can cause crashes or allow attackers to execute harmful code. Microsoft Edge, which is based on Chromium, includes this fix in its version 146.0.3856.72 and later. Users should update Edge to this version or newer to stay protected.

Technical explanation

How the issue affects the environment

CVE-2026-4450 is an out-of-bounds write vulnerability in the V8 JavaScript engine within Chromium. Out-of-bounds writes occur when the program writes data outside the intended memory boundaries, potentially corrupting memory, crashing the program, or allowing execution of arbitrary code. Since Microsoft Edge (Chromium-based) integrates Chromium's code, it is affected by this vulnerability. The issue was addressed in Chromium version 146.0.7680.154, which aligns with Microsoft Edge version 146.0.3856.72. Updating to this version replaces vulnerable components with corrected code that properly bounds memory writes in V8.

Operational impact

Why teams should care

If left unaddressed, this vulnerability could be exploited to conduct arbitrary code execution attacks via crafted web content, potentially compromising user data or device integrity when using Microsoft Edge. This may lead to data breaches, service interruptions, and loss of customer trust. Updating mitigates these risks by removing the vulnerable code paths.

Immediate action

Update Microsoft Edge (Chromium-based) to version 146.0.3856.72 or later to obtain the patched Chromium version that addresses this vulnerability. Ensure all systems running the browser are brought to this release. After updating, verify the browser version in 'Help and Feedback' > 'About Microsoft Edge' to confirm the fix is applied.

Affected and fixed releases

Affected versionsMicrosoft Edge versions before 146.0.3856.72
Fixed versions146.0.3856.72

Temporary risk reduction

No separate workaround was supplied in the source feed. Use the official vendor advisory before changing production controls.

Evidence and validation checklist

  • Microsoft documentation confirms the vulnerability in Chromium's V8 engine.
  • Microsoft Edge version 146.0.3856.72 is based on a fixed Chromium build (146.0.7680.154).
  • The Advisory directs users to update to Microsoft Edge 146.0.3856.72.
  • No exploitation status or known active attacks reported in the advisory.

Authoritative reference

Microsoft Security Response Center

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source