CVE-2026-3539Disclosure

MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Rejected reason: Determined a bug and not a vulnerability

4.0/ 10 priority

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-03-04); latest day: 1
  • 7 total mentions across 4 days

Deep dive

Activity timeline7 mentions / 4d
01223Mentions · 2026-03-04: 3Mentions · 2026-03-05: 2Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-04: 3Technical Details · 2026-03-05: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 103-0403-0503-0803-10
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-043
Disclosure2General1
2026-03-052
Disclosure1General1
2026-03-081
Disclosure1
2026-03-101
Patch1
Full discourse7 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3539: HIGH] Security flaw in Google Chrome (pre-145.0.7632.159) DevTools allowed hackers to exploit heap corruption with malicious extensions. Severity: High.#cve,CVE-2026-3539,#cybersecurity https://cvefind.com/CVE-2026-3539

    Post summary

    The tweet discloses a high‑severity heap corruption flaw in older Google Chrome DevTools that can be triggered by malicious extensions, without providing active exploitation, patch, or PoC details.

    0002070
    597 followersView on X
  • İmam Gazali@boo8ow1923
    Patch

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The text enumerates multiple critical CVEs with CVSS scores, highlights signs of active exploitation for at least one zero‑day, and provides detailed patch guidance for affected systems, underscoring the urgency of applying updates.

    0100071
    48 followersView on X
  • とれとれたまたま!@ejGyLgtl1l34519
    Disclosure

    ・CVE-2026-3536:Integer overflow in ANGLE(Critical) ・CVE-2026-3537:Object lifecycle issue in PowerVR(Critical) ・CVE-2026-3538:Integer overflow in Skia(Critical) ・CVE-2026-3539:Object lifecycle issue in DevTools(High)  つづく~

    Post summary

    The text lists several CVEs with their type (e.g., integer overflow, object lifecycle issue) and severity (Critical, High) but provides no further details such as PoC, exploit code, patches, or evidence of active exploitation.

    1000053
    134 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-3539 - High Object lifecycle issue in DevTools in Google Chrome prior to 145.0.7632.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via... https://www.thehackerwire.com/vulnerability/CVE-2026-3539/ https://t.co/zONkfv3WtK

    Post summary

    The tweet references CVE‑2026‑3539, noting an object lifecycle flaw in Chrome's DevTools that could lead to heap corruption, but it offers no PoC, exploit, patch, or evidence of active exploitation.

    0000159
    124 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-3539 Object lifecycle issue in DevTools in Google Chrome prior to 145.0.7632.159 allowed an attacker who convinced a user to install a malicious extension to potentially exp… https://www.cve.org/CVERecord?id=CVE-2026-3539 ----- Traducción: CVE-2026-3539 Pro… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-3539, describing an object lifecycle flaw in Chrome’s DevTools that may allow attackers to gain escalation via malicious extensions, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0001037
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3539 Object lifecycle issue in DevTools in Google Chrome prior to 145.0.7632.159 allowed an attacker who convinced a user to install a malicious extension to potentially exp… https://www.cve.org/CVERecord?id=CVE-2026-3539

    Post summary

    The text announces CVE-2026-3539, describing an object lifecycle issue in Chrome DevTools that could allow malicious extensions to exploit users, but no PoC, exploit, or patch details are provided.

    00010206
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3539 Object Lifecycle Vulnerability in Chrome DevTools Enabling Heap Corruption via Extension https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3539

    Post summary

    An announcement of CVE-2026-3539, a heap corruption bug in Chrome DevTools triggered via an extension, with a link to the vulnerability details.

    0000059
    4.0K followersView on X

Explore more