alpine · CVE-2026-4458

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2026-4458: 1 source package rows (qt6-qtwebengine); 2 state rows across 2 repos (3.23-community, edge-community); fixed 2, open 0.

Description:

Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)

cvelogic Threat Intelligence