CVE-2026-3536Patch(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472CWE-190

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 16 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 4 mentions (2026-03-05); latest day: 4
  • 16 total mentions across 6 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline16 mentions / 6d
01234Mentions · 2026-03-04: 2Mentions · 2026-03-05: 4Mentions · 2026-03-06: 4Mentions · 2026-03-07: 1Mentions · 2026-03-08: 1Mentions · 2026-03-10: 4Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-06: 4Patch / Workaround · 2026-03-10: 4Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 2Technical Details · 2026-03-06: 2Technical Details · 2026-03-10: 303-0403-0503-0603-0703-0803-10
Signal classification3 categories
Patch
850.0%
Disclosure
531.3%
General
318.8%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-054
Disclosure2General1Patch1
2026-03-064
Patch4
2026-03-071
General1
2026-03-081
General1
2026-03-104
Disclosure1Patch3
Full discourse16 posts
  • xvonfers@xvonfers
    Patch

    (CVE-2026-3536)[$33000][485622239][ANGLE][Vulkan]Integer overflow in texture size calculation -> OOBW??? https://chromium-review.googlesource.com/c/angle/angle/+/7595734 https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html Reported by @cinzinga_

    Post summary

    The post announces CVE-2026-3536 as an integer overflow in ANGLE's Vulkan implementation, cites the relevant review, and links to a Chromium release update that presumably contains the fix, but provides no PoC, exploit code, or evidence of active exploitation.

    23022182.3K
    4.9K followersView on X
  • くまかば@kumakaba
    General

    Google Chromeの脆弱性CVE-2026-3536~3538のヤツ、Microsoft DefenderのVulnerability notificationでお知らせ来てたからどんなんかと思ったらめっちゃヤバかったw https://www.cve.org/CVERecord?id=CVE-2026-3536 https://www.cve.org/CVERecord?id=CVE-2026-3537 https://www.cve.org/CVERecord?id=CVE-2026-3538

    Post summary

    The post merely notes that Microsoft Defender flagged three Google Chrome CVEs as serious, but provides no technical details, PoC, or exploit information.

    12020215
    683 followersView on X
  • jericho@attritionorg
    General

    @Forbes re: https://www.forbes.com/sites/daveywinder/2026/03/06/google-confirms-trio-of-critical-chrome-security-vulnerabilities/ In a header you say "Google Chrome CVE-2026-3536, CVE-2026-3536, And CVE-2026-3536 Security Vulnerabilities Confirmed" - all three same IDs. Correct IDs are below that in the body.

    Post summary

    The tweet notes a mistake in Forbes’ headline where all three CVE IDs were listed identically; the correct unique IDs appear later in the article.

    01010179
    17.6K followersView on X
  • İmam Gazali@boo8ow1923
    Disclosure

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The post enumerates current critical and zero‑day CVEs, outlines their technical impact, and provides patching guidance for affected systems.

    0100071
    48 followersView on X
  • とれとれたまたま!@ejGyLgtl1l34519
    General

    ・CVE-2026-3536:Integer overflow in ANGLE(Critical) ・CVE-2026-3537:Object lifecycle issue in PowerVR(Critical) ・CVE-2026-3538:Integer overflow in Skia(Critical) ・CVE-2026-3539:Object lifecycle issue in DevTools(High)  つづく~

    Post summary

    The text lists four newly disclosed CVEs with critical and high severity designations but does not provide any details on PoC, exploit, active exploitation, patches, or technical specifics.

    1000053
    134 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 145.0.7632.159/160 (Windows および Mac) および 145.0.7632.159 (Linux) をリリース. CVE ベースで Critical 3 件,High 7 件の脆弱性に対処. ・CVE-2026-3536 ・CVE-2026-3537 ・CVE-2026-3538 https://x.com/kawn2020/status/2029867521466323324

    Post summary

    Google released a new Chrome update that patches three critical CVEs, providing a straightforward patch notice without any exploit or false-positive information.

    1000099
    89 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3536 Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.… https://www.cve.org/CVERecord?id=CVE-2026-3536 ----- Traducción: CVE-2026-3536 des… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-3536, an integer overflow in ANGLE within older Chrome versions, highlight­ing potential out-of-bounds memory access via crafted HTML pages.

    0001044
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3536 Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.… https://www.cve.org/CVERecord?id=CVE-2026-3536

    Post summary

    The text announces CVE-2026-3536, an integer overflow in ANGLE affecting Google Chrome before version 145.0.7632.159, which could enable a remote attacker to perform out‑of‑bounds memory access using a crafted HTML page.

    00010271
    56.6K followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    Google's Chrome 145 emergency update (Mar 3, 2026) patches 10 CVEs: heap overflows in WebCodecs/Skia, V8/WASM issues, CSS bugs. Critical ones like CVE-2026-3536. Win/macOS/Linux: 145.0.7632.159+. https://windowsforum.com/threads/chrome-145-march-3-2026-emergency-update-fixes-10-critical-cves.404245/

    Post summary

    The announcement is a patch update for ten critical Chrome CVEs, providing details on the vulnerabilities and the affected versions.

    00000129
    174 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security patch for #Chromium on #Fedora 42 is out. Version 145.0.7632.159 addresses CVE-2026-3536 through 3545, including integer overflows in ANGLE/Skia and inappropriate implementations in V8/WebAssembly. Read more: 👉 https://tinyurl.com/4tdv2fm2 #Security https://t.co/UtjMKzzApZ

    Post summary

    The tweet announces that a critical patch for Chromium on Fedora 42 is available, specifically addressing CVE-2026-3536 to 3545, focusing on integer overflows and improper WebAssembly handling.

    0000050
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #Fedora 43: Chromium 145.0.7632.159 patches 10 CVEs (CVE-2026-3536 to 3545). Critical fixes for ANGLE, Skia, V8, and WebAssembly. Read more: 👉 https://tinyurl.com/3xnkfshe #Security https://t.co/HEU67x6IdT

    Post summary

    Fedora 43 releases a new Chromium update that patches 10 CVEs, addressing critical issues in ANGLE, Skia, V8, and WebAssembly.

    0000054
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads up, #Debian self-hosters and sysadmins. DSA-6157-1 is out for Chromium, addressing CVE-2026-3536 (arbitrary code execution) and friends. Read more: 👉 https://tinyurl.com/4hrbcfek #Security https://t.co/LcmoO3aSdy

    Post summary

    A Debian security advisory (DSA-6157‑1) for Chromium addressing CVE‑2026‑3536, an arbitrary code execution vulnerability, has been released; users should apply the update.

    0000063
    1.3K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    Google、Chromeの致命的な脆弱性3件を含む脆弱性 10件を修正(CVE-2026-3536,CVE-2026-3537,CVE-2026-3538) https://rocket-boys.co.jp/security-measures-lab/google-chrome-fixes-10-bugs-including-3-critical-cve-2026-3536-3537-3538/

    Post summary

    Google announced a patch for 10 Chrome vulnerabilities, including three critical ones (CVE‑2026‑3536, CVE‑2026‑3537, CVE‑2026‑3538).

    0000090
    47 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの致命的な脆弱性3件を含む脆弱性 10件を修正(CVE-2026-3536,CVE-2026-3537,CVE-2026-3538) https://rocket-boys.co.jp/security-measures-lab/google-chrome-fixes-10-bugs-including-3-critical-cve-2026-3536-3537-3538/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The post announces Google Chrome’s release of patches that fix 10 bugs, including three critical CVEs.

    00000162
    328 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-3536) https://vuldb.com/?id.348831

    Post summary

    A newly identified critical Chrome vulnerability (CVE-2026-3536) is noted on VULDB; however, no technical or remediation details are supplied.

    0000094
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3536 Integer Overflow in ANGLE Renderer Enables Remote Memory Access in Google Chrome https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3536

    Post summary

    The text announces CVE-2026-3536 as an integer overflow in Chrome's ANGLE Renderer that permits remote memory access, providing basic technical details but no evidence of exploitation, PoC, or mitigation.

    0000068
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more