CVE-2026-3537Patch(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787CWE-1091

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 13 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-03-05); latest day: 1
  • 13 total mentions across 6 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline13 mentions / 6d
01223Mentions · 2026-03-04: 2Mentions · 2026-03-05: 3Mentions · 2026-03-06: 3Mentions · 2026-03-08: 1Mentions · 2026-03-09: 3Mentions · 2026-03-10: 1Active Exploitation · 2026-03-09: 1Patch / Workaround · 2026-03-06: 3Patch / Workaround · 2026-03-09: 3Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 2Technical Details · 2026-03-10: 103-0403-0503-0603-0803-0903-10
Signal classification3 categories
Patch
646.2%
Disclosure
538.5%
General
215.4%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-053
Disclosure2General1
2026-03-063
Patch3
2026-03-081
Disclosure1
2026-03-093
Patch3
2026-03-101
General1
Full discourse13 posts
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-3537)[$32000][474266014][PowerVR/IMG]Driver internally frees/corrupts the previously-bound complete FBO when a new complete FBO transitions into being the active complete binding(UAF) https://chromium-review.googlesource.com/c/chromium/src/+/7533383 https://t.co/jhgbnvrDQC

    Post summary

    The tweet discloses a CVE-2026-3537 vulnerability in PowerVR/IMG drivers, describing a use‑after‑free caused by internal FBO state handling and linking to a Chromium review.

    0101491.6K
    4.9K followersView on X
  • くまかば@kumakaba
    General

    Google Chromeの脆弱性CVE-2026-3536~3538のヤツ、Microsoft DefenderのVulnerability notificationでお知らせ来てたからどんなんかと思ったらめっちゃヤバかったw https://www.cve.org/CVERecord?id=CVE-2026-3536 https://www.cve.org/CVERecord?id=CVE-2026-3537 https://www.cve.org/CVERecord?id=CVE-2026-3538

    Post summary

    The user notes Google Chrome CVEs 2026‑3536 to 3538 and mentions a Microsoft Defender vulnerability notification, but provides no technical details, exploit information, patch information, or evidence of exploitation.

    12020215
    683 followersView on X
  • İmam Gazali@boo8ow1923
    General

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The post enumerates several high-severity CVEs, zero-day indicators, and patch updates, but does not provide PoC code or evidence of active exploitation, focusing instead on risk assessment and mitigation.

    0100071
    48 followersView on X
  • FK94 Security@FK94SECURITY
    Patch

    Chrome Android tenía un fallo (CVE-2026-3537) que dejaba ejecutar código malicioso. Si no actualizás a la 145+, cualquier web te hackea. Y sí: tu versión probablemente es vieja

    Post summary

    The tweet warns that Chrome Android users with versions older than 145 are exposed to CVE‑2026‑3537, which can lead to arbitrary code execution via compromised websites, and urges users to update to version 145 or later.

    1000032
    6 followersView on X
  • とれとれたまたま!@ejGyLgtl1l34519
    Disclosure

    ・CVE-2026-3536:Integer overflow in ANGLE(Critical) ・CVE-2026-3537:Object lifecycle issue in PowerVR(Critical) ・CVE-2026-3538:Integer overflow in Skia(Critical) ・CVE-2026-3539:Object lifecycle issue in DevTools(High)  つづく~

    Post summary

    The snippet announces several new CVEs with brief technical descriptors and severity levels, but lacks details on PoCs, exploitation, patches, or active use.

    1000053
    134 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 145.0.7632.159/160 (Windows および Mac) および 145.0.7632.159 (Linux) をリリース. CVE ベースで Critical 3 件,High 7 件の脆弱性に対処. ・CVE-2026-3536 ・CVE-2026-3537 ・CVE-2026-3538 https://x.com/kawn2020/status/2029867521466323324

    Post summary

    Google released Chrome update 145.0.7632.159/160 (Windows and Mac) and 145.0.7632.159 (Linux) addressing three critical CVEs (CVE-2026-3536, 3537, 3538) plus seven high‑severity ones; the tweet is a patch announcement.

    1000099
    89 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3537 Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… https://www.cve.org/CVERecord?id=CVE-2026-3537 ----- Traducción: CVE-2026-3537 Pro… http://infoflow.cloud`

    Post summary

    The tweet links to a CVE record and summarizes a CVE‑2026‑3537 object lifecycle issue in PowerVR that could allow a remote attacker to induce heap corruption via crafted HTM.

    0001058
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3537 Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM… https://www.cve.org/CVERecord?id=CVE-2026-3537

    Post summary

    The post announces CVE-2026-3537, detailing a heap‑corruption risk in Chrome for Android, but offers no PoC, exploit, patch, or active exploitation evidence.

    00010270
    56.6K followersView on X
  • FK94 Security@FK94SECURITY
    Patch

    Actualizá tu Chrome en Android: CVE-2026-3537 permite ejecución remota de código. Protegé tu dispositivo con la última versión 145.0.7632.159+. Chequeá tu seguridad aquí: http://fk94security.com/free-resources/security-score #Android #Seguridad

    Post summary

    The post warns that CVE‑2026‑3537 allows remote code execution in Chrome on Android and urges users to update to the latest version 145.0.7632.159+.

    0000039
    6 followersView on X
  • 【學】@manabu2111
    Patch

    「Microsoft Edge」でセキュリティ修正、致命的な整数オーバーフローの脆弱性などに対処 - 窓の杜 https://forest.watch.impress.co.jp/docs/news/2091507.html 、これらの脆弱性は、(詳細は記事を参考に)、同じく「Chromium」をベースとする「Google Chrome」でも先日修正済みだ(「Chrome」には追加で「CVE-2026-3537」が修正)

    Post summary

    The article reports that Microsoft Edge and Google Chrome have applied a patch for a critical integer overflow vulnerability, including CVE-2026-3537.

    0000095
    2.2K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    Google、Chromeの致命的な脆弱性3件を含む脆弱性 10件を修正(CVE-2026-3536,CVE-2026-3537,CVE-2026-3538) https://rocket-boys.co.jp/security-measures-lab/google-chrome-fixes-10-bugs-including-3-critical-cve-2026-3536-3537-3538/

    Post summary

    The article announces Google Chrome’s patching of ten vulnerabilities, including three critical CVEs (CVE-2026-3536, CVE-2026-3537, CVE-2026-3538).

    0000090
    47 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの致命的な脆弱性3件を含む脆弱性 10件を修正(CVE-2026-3536,CVE-2026-3537,CVE-2026-3538) https://rocket-boys.co.jp/security-measures-lab/google-chrome-fixes-10-bugs-including-3-critical-cve-2026-3536-3537-3538/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Google Chrome has released a patch that fixes ten vulnerabilities, including three critical CVEs (CVE-2026-3536, CVE-2026-3537, CVE-2026-3538).

    00000162
    328 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3537 Heap Corruption in PowerVR on Google Chrome for Android via Malicious HTML https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3537

    Post summary

    The text announces CVE-2026-3537 as a heap corruption vulnerability in PowerVR on Chrome for Android, providing basic technical details but no proof of concept, exploit, or patch information.

    0000080
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome-android-
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more