CVE-2026-3063Patch(apple / chrome)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via DevTools. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-24); latest day: 3
  • 7 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline7 mentions / 2d
01234Mentions · 2026-02-24: 4Mentions · 2026-02-25: 3Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 2Technical Details · 2026-02-24: 3Technical Details · 2026-02-25: 102-2402-25
Signal classification3 categories
Patch
342.9%
Disclosure
228.6%
General
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-244
Disclosure2General1Patch1
2026-02-253
General1Patch2
Full discourse7 posts
  • Misbar | مسبار@MisbarSec
    Patch

    تحديث عاجل لـ Google Chrome لسد ثغرات خطيرة جوجل أصدرت تحديث أمني طارئ لمتصفح Chrome، وصل الإصدار 145.0.7632.116/117 لنظامي Windows و macOS. هذا التحديث يعالج ثلاث ثغرات ذات خطورة عالية، بما في ذلك CVE-2026-3063، CVE-2026-3062، و CVE-2026-3061. تجاهل هذا التحديث يعرض المستخدمين لخطر استغلال هذه الثغرات. خطوات الحماية: * حدث متصفح Chrome فورًا إلى أحدث إصدار. * فعل التحديثات التلقائية في إعدادات المتصفح. * راجع سجل التحديثات للتأكد من تثبيت النسخة الجديدة. https://cybersecuritynews.com/google-chrome-emergency-security-update/ #الأمن_السيبراني #Chrome #تحديث_أمني

    Post summary

    Google Chrome issued an emergency update to patch three high‑severity CVEs (CVE‑2026‑3063, CVE‑2026‑3062, CVE‑2026‑3061). Users are urged to update immediately to mitigate potential exploitation.

    0002068
    53 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Google Rushes Emergency Chrome Patch for 3 High-Severity Flaws (Media, Tint, DevTools) Google released an emergency Chrome Stable update (145.0.7632.116/117 for Windows/macOS; 144.0.7559.116 for Linux) fixing three high-severity bugs—CVE-2026-3061 (Media OOB read), CVE-2026-3062 (Tint OOB read/write), and CVE-2026-3063 (DevTools inappropriate implementation)—that could enable memory corruption, data leakage, or RCE chains if weaponized. Rapid patching is critical because browser bugs are prime initial-access vectors at internet scale. 🎯 Target: Global #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/google-rushes-emergency-chrome-update/

    Post summary

    Google issued an emergency Chrome patch to address three high‑severity CVEs that could enable memory corruption, data leakage, or RCE, underscoring the urgency of applying the update.

    10010135
    196 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3063 Chrome DevTools Privilege Escalation via Malicious Extension Injec... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3063 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new CVE (CVE-2026-3063) affecting Chrome DevTools via malicious extension injection is announced, but no PoC, exploit, patch, or active exploitation details are provided.

    0001050
    4.0K followersView on X
  • 【學】@manabu2111
    General

    CVE-2026-3063、Inappropriate implementation in DevTools(High)、 深刻度の評価は、いずれも4段階中上から2番目の「High」

    Post summary

    The text references CVE‑2026‑3063 and notes a high severity rating, but provides no additional details or actionable information.

    0000038
    2.2K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの安定版で3件の脆弱性を緊急修正(CVE-2026-3061、CVE-2026-3062、CVE-2026-3063) https://rocket-boys.co.jp/security-measures-lab/google-chrome-stable-emergency-fixes-cve-2026-3061-cve-2026-3062-cve-2026-3063/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Google Chrome stable releases emergency patches for three CVEs (CVE-2026-3061, CVE-2026-3062, CVE-2026-3063).

    00000149
    318 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Google ❗ CVE-2026-3063 ❗ CVE-2026-3062 ❗ CVE-2026-3061 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-google-3/ https://t.co/tUNWCPmdsH

    Post summary

    The post lists three CVE identifiers for Google products and directs readers to external links for more information, but provides no further details.

    00000163
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3063 Inappropriate implementation in DevTools in Google Chrome prior to 145.0.7632.116 allowed an attacker who convinced a user to install a malicious extension to inject sc… https://www.cve.org/CVERecord?id=CVE-2026-3063

    Post summary

    The text announces CVE‑2026‑3063, a Chrome DevTools flaw that could let malicious extensions inject code, but it does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00000192
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more