CVE-2026-3062Disclosure(apple / chrome)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 6 mentions (2026-02-24); latest day: 1
  • 12 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline12 mentions / 4d
02356Mentions · 2026-02-24: 6Mentions · 2026-02-25: 4Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Patch / Workaround · 2026-02-24: 2Patch / Workaround · 2026-02-25: 4Technical Details · 2026-02-24: 4Technical Details · 2026-02-25: 2Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2402-2502-2702-28
Signal classification2 categories
Disclosure
650.0%
Patch
650.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-02-246
Disclosure4Patch2
2026-02-254
Patch4
2026-02-271
Disclosure1
2026-02-281
Disclosure1
Full discourse12 posts
  • xvonfers@xvonfers
    Patch

    (CVE-2026-3062)[483751167][tint][transform]Array size overflow when doing override substitution(override array size overflow) -> OOBRW https://dawn-review.googlesource.com/c/dawn/+/290475 https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_23.html Reported by cinzinga https://t.co/hBmDVJnILj

    Post summary

    CVE-2026-3062 is an array size overflow vulnerability in Dawn’s override substitution, and a patch has been released in the Chrome stable channel update.

    03028122.1K
    4.8K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    تحديث عاجل لـ Google Chrome لسد ثغرات خطيرة جوجل أصدرت تحديث أمني طارئ لمتصفح Chrome، وصل الإصدار 145.0.7632.116/117 لنظامي Windows و macOS. هذا التحديث يعالج ثلاث ثغرات ذات خطورة عالية، بما في ذلك CVE-2026-3063، CVE-2026-3062، و CVE-2026-3061. تجاهل هذا التحديث يعرض المستخدمين لخطر استغلال هذه الثغرات. خطوات الحماية: * حدث متصفح Chrome فورًا إلى أحدث إصدار. * فعل التحديثات التلقائية في إعدادات المتصفح. * راجع سجل التحديثات للتأكد من تثبيت النسخة الجديدة. https://cybersecuritynews.com/google-chrome-emergency-security-update/ #الأمن_السيبراني #Chrome #تحديث_أمني

    Post summary

    Google Chrome issued an emergency update to patch three high‑severity CVEs (CVE‑2026‑3063, CVE‑2026‑3062, CVE‑2026‑3061). Users are urged to update immediately to mitigate potential exploitation.

    0002068
    53 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Google Rushes Emergency Chrome Patch for 3 High-Severity Flaws (Media, Tint, DevTools) Google released an emergency Chrome Stable update (145.0.7632.116/117 for Windows/macOS; 144.0.7559.116 for Linux) fixing three high-severity bugs—CVE-2026-3061 (Media OOB read), CVE-2026-3062 (Tint OOB read/write), and CVE-2026-3063 (DevTools inappropriate implementation)—that could enable memory corruption, data leakage, or RCE chains if weaponized. Rapid patching is critical because browser bugs are prime initial-access vectors at internet scale. 🎯 Target: Global #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/google-rushes-emergency-chrome-update/

    Post summary

    Google issued an emergency Chrome patch for three high‑severity CVEs, detailing the affected versions and the potential for memory corruption, data leakage, or RCE if left unpatched.

    10010135
    196 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Google Chrome (CVE-2026-3062) https://vuldb.com/?id.347427

    Post summary

    A new vulnerability (CVE-2026-3062) in Google Chrome has been disclosed with increased severity, as reported on vuldb.com.

    0001191
    2.1K followersView on X
  • 【學】@manabu2111
    Patch

    「Google Chrome」に3件の脆弱性、境界外読み取り・書き込みの欠陥などに対処 - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2087987.html 、本バージョンでは、以下の3件の脆弱性が修正された、 CVE-2026-3061、Out of bounds read in Media(High)、 CVE-2026-3062、Mut of bounds read and write in Tint(High)、(続く)

    Post summary

    The article reports that Google Chrome has patched three CVEs involving out‑of‑bounds read/write vulnerabilities, providing CVE identifiers and severity ratings.

    1000074
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3062 Out of Bounds Memory Access in Google Chrome Tint on Mac Before 145.0.7632.116 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3062

    Post summary

    A new CVE-2026-3062 vulnerability is disclosed, describing an out‑of‑bounds memory access in Google Chrome Tint on Mac before version 145.0.7632.116.

    0001060
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3062 (CVSS:9.8, CRITICAL) is Modified. Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perfor..https://nvd.nist.gov/vuln/detail/CVE-2026-3062 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post points out CVE-2026-3062, noting a critical CVSS score and out‑of‑bounds read/write flaw in Chrome’s Tint on Mac, but does not refer to a PoC, exploit, or patch.

    0000025
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-3062 (CVSS:9.8, CRITICAL) is Modified. Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perfor..https://nvd.nist.gov/vuln/detail/CVE-2026-3062 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE‑2026‑3062 is a critical out‑of‑bounds read/write flaw in Google Chrome’s Tint component on macOS, disclosed with a CVSS score of 9.8 and a reference to the NVD entry.

    0000033
    173 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical Chromium security update for #openSUSE users (Backports SLE-15-SP6). The update addresses CVE-2026-3061 and CVE-2026-3062, which are out-of-bounds memory flaws that could compromise your system. Read more: 👉 https://tinyurl.com/yc2fxs5u #Security https://t.co/6B7bM9wMPx

    Post summary

    The tweet announces a critical Chromium update for openSUSE that patches CVE-2026-3061 and CVE-2026-3062, which are out-of-bounds memory flaws that could compromise systems.

    0000048
    1.3K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの安定版で3件の脆弱性を緊急修正(CVE-2026-3061、CVE-2026-3062、CVE-2026-3063) https://rocket-boys.co.jp/security-measures-lab/google-chrome-stable-emergency-fixes-cve-2026-3061-cve-2026-3062-cve-2026-3063/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Google Chrome stable releases emergency patches for CVE-2026-3061, CVE-2026-3062, and CVE-2026-3063.

    00000149
    318 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Google ❗ CVE-2026-3063 ❗ CVE-2026-3062 ❗ CVE-2026-3061 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-google-3/ https://t.co/tUNWCPmdsH

    Post summary

    The post lists three CVEs affecting Google products and links to a page for additional information.

    00000163
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3062 Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML… https://www.cve.org/CVERecord?id=CVE-2026-3062

    Post summary

    CVE-2026-3062 describes an out‑of‑bounds memory access vulnerability in Google Chrome’s Tint component on macOS, affecting versions prior to 145.0.7632.116, and allows remote attackers to exploit it via crafted HTML.

    00000185
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more