Google Chrome < 145.0.7632.45 Multiple Vulnerabilities

critical Nessus Plugin ID 298676

Synopsis

A web browser installed on the remote macOS host is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote macOS host is prior to 145.0.7632.45. It is, therefore, affected by multiple vulnerabilities as referenced in the 2026_02_stable-channel-update-for-desktop_10 advisory.

- Use after free in Ozone. (CVE-2026-2321)

- Use after free in CSS. (CVE-2026-2313)

- Heap buffer overflow in Codecs. (CVE-2026-2314)

- Inappropriate implementation in WebGPU. (CVE-2026-2315)

- Insufficient policy enforcement in Frames. (CVE-2026-2316)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Google Chrome version 145.0.7632.45 or later.

See Also

http://www.nessus.org/u?c6b2a722

https://crbug.com/467297219

https://crbug.com/478560268

https://crbug.com/479242793

https://crbug.com/422531206

https://crbug.com/464173573

https://crbug.com/363930141

https://crbug.com/40071155

https://crbug.com/435684924

https://crbug.com/461877477

https://crbug.com/470928605

https://crbug.com/467442136

Plugin Details

Severity: Critical

ID: 298676

File Name: macosx_google_chrome_145_0_7632_45.nasl

Version: 1.1

Type: local

Agent: macosx

Published: 2/11/2026

Updated: 2/11/2026

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-2321

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: installed_sw/Google Chrome

Exploit Ease: No known exploits are available

Patch Publication Date: 2/10/2026

Vulnerability Publication Date: 2/10/2026

Reference Information

CVE: CVE-2026-2313, CVE-2026-2314, CVE-2026-2315, CVE-2026-2316, CVE-2026-2317, CVE-2026-2318, CVE-2026-2319, CVE-2026-2320, CVE-2026-2321, CVE-2026-2322, CVE-2026-2323