CVE-2026-3538Patch(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-472CWE-191

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 5 mentions (2026-03-05); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline12 mentions / 5d
01345Mentions · 2026-03-04: 2Mentions · 2026-03-05: 5Mentions · 2026-03-06: 3Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-05: 3Patch / Workaround · 2026-03-06: 3Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 4Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 103-0403-0503-0603-0803-10
Signal classification3 categories
Patch
650.0%
Disclosure
433.3%
General
216.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-055
Disclosure1General1Patch3
2026-03-063
Patch3
2026-03-081
Disclosure1
2026-03-101
General1
Full discourse12 posts
  • symeon@symeonp
    Patch

    https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html Critical CVE-2026-3538: Integer overflow in Skia, latest Chrome releases addresses one critical vuln I reported a couple of weeks ago. Incredible!

    Post summary

    Chrome’s latest stable channel update includes a patch for CVE-2026-3538, an integer overflow vulnerability in Skia, addressing a critical issue reported earlier.

    57079437.6K
    1.2K followersView on X
  • xvonfers@xvonfers
    Patch

    (CVE-2026-3538)[484983991][Skia][ganesh]Integer overflow https://skia-review.googlesource.com/c/skia/+/1169977 https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html Reported by Symeon Paraschoudis

    Post summary

    CVE‑2026‑3538, an integer overflow in Skia, was fixed and included in the March 2026 Chrome stable release.

    130951.7K
    4.9K followersView on X
  • くまかば@kumakaba
    General

    Google Chromeの脆弱性CVE-2026-3536~3538のヤツ、Microsoft DefenderのVulnerability notificationでお知らせ来てたからどんなんかと思ったらめっちゃヤバかったw https://www.cve.org/CVERecord?id=CVE-2026-3536 https://www.cve.org/CVERecord?id=CVE-2026-3537 https://www.cve.org/CVERecord?id=CVE-2026-3538

    Post summary

    The tweet points out Google Chrome CVEs 2026‑3536 through 2026‑3538, shares links to CVE.org, but offers no additional technical, exploit, or mitigation information.

    12020215
    683 followersView on X
  • İmam Gazali@boo8ow1923
    General

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The post lists numerous critical CVEs, indicates active exploitation for several zero‑days, and provides patch recommendations for Windows, Android, Chrome, and Cisco products.

    0100071
    48 followersView on X
  • とれとれたまたま!@ejGyLgtl1l34519
    Disclosure

    ・CVE-2026-3536:Integer overflow in ANGLE(Critical) ・CVE-2026-3537:Object lifecycle issue in PowerVR(Critical) ・CVE-2026-3538:Integer overflow in Skia(Critical) ・CVE-2026-3539:Object lifecycle issue in DevTools(High)  つづく~

    Post summary

    The passage announces four newly disclosed critical CVEs, each with a specific vulnerability type and severity, indicating a straightforward disclosure of security issues.

    1000053
    134 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 145.0.7632.159/160 (Windows および Mac) および 145.0.7632.159 (Linux) をリリース. CVE ベースで Critical 3 件,High 7 件の脆弱性に対処. ・CVE-2026-3536 ・CVE-2026-3537 ・CVE-2026-3538 https://x.com/kawn2020/status/2029867521466323324

    Post summary

    Google Chrome released a security update that patches three critical CVEs (CVE-2026-3536, 2026-3537, 2026-3538) for Windows, macOS, and Linux.

    1000099
    89 followersView on X
  • VulnTracker@vuln_tracker
    Patch

    @symeonp Nice to see a quick turnaround on CVE-2026-3538. The latest Google Chrome stable update includes a fix for the critical Skia integer overflow. If you haven’t updated yet, it’s probably a good time. We’re tracking it on https://vulntracker.io/cves/CVE-2026-3538

    Post summary

    The tweet highlights that Google Chrome’s latest stable update contains a fix for CVE‑2026‑3538, an integer overflow in Skia, and urges users to update.

    00010146
    390 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    Google、Chromeの致命的な脆弱性3件を含む脆弱性 10件を修正(CVE-2026-3536,CVE-2026-3537,CVE-2026-3538) https://rocket-boys.co.jp/security-measures-lab/google-chrome-fixes-10-bugs-including-3-critical-cve-2026-3536-3537-3538/

    Post summary

    Google Chrome released patches for ten vulnerabilities, including three critical CVEs (CVE‑2026‑3536, CVE‑2026‑3537, CVE‑2026‑3538).

    0000090
    47 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの致命的な脆弱性3件を含む脆弱性 10件を修正(CVE-2026-3536,CVE-2026-3537,CVE-2026-3538) https://rocket-boys.co.jp/security-measures-lab/google-chrome-fixes-10-bugs-including-3-critical-cve-2026-3536-3537-3538/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    The article reports that Google Chrome has released a patch addressing ten bugs, including three critical ones (CVE-2026-3536, CVE-2026-3537, CVE-2026-3538).

    00000162
    328 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3538 Integer Overflow in Skia Rendering Engine Enables Remote Memory Access in Chrome https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3538

    Post summary

    The text announces CVE-2026-3538, describing an integer overflow in Chrome's Skia engine that allows remote memory access, but provides no proof of concept, exploit code, patch, or evidence of active exploitation.

    0000066
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3538 Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. … https://www.cve.org/CVERecord?id=CVE-2026-3538 ----- Traducción: CVE-2026-3538 Des… http://infoflow.cloud`

    Post summary

    This report announces CVE-2026-3538, an integer overflow in Skia used by Google Chrome, capable of out-of-bounds memory access through crafted HTML. No proof‑of‑concept, exploit code, patch, or evidence of active exploitation is included.

    0000041
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3538 Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. … https://www.cve.org/CVERecord?id=CVE-2026-3538

    Post summary

    CVE‑2026‑3538 is an integer‑overflow vulnerability in Skia used by Chrome versions before 145.0.7632.159 that could allow a malicious web page to cause out‑of‑bounds memory access. The post describes the issue but does not mention a PoC, exploit code, active attacks, or patches.

    00000251
    56.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more