CVE-2026-3542Disclosure(apple / chrome)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Disclousre: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-03-04); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-04: 2Mentions · 2026-03-05: 2Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Mentions · 2026-06-22: 1Exploit Tool / Code · 2026-06-22: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 1Technical Details · 2026-06-22: 103-0403-0503-0603-0803-1006-22
Signal classification4 categories
Disclosure
562.5%
Disclousre
112.5%
Active Exploitation
112.5%
Exploit
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-052
Disclosure1Disclousre1
2026-03-061
Disclosure1
2026-03-081
Disclosure1
2026-03-101
Active Exploitation1
2026-06-221
Exploit1
Full discourse8 posts
  • QYmag1c@QYmag1c
    Disclosure

    Two new Chrome V8 CVEs assigned (CVE-2026-3542 and CVE-2026-3543) 🎯 Big thanks to @bjrjk for the help and guidance! https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html

    Post summary

    Two new Chrome V8 CVEs were announced; the post provides no additional exploitation or mitigation details.

    28065263.5K
    75 followersView on X
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-3542)[485152421][asm.js]Heap-BoF in ShiftExpression(asm.js , asm parser, invalid Wasm modules being generated) https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html Reported by @QYmag1c

    Post summary

    A new heap buffer overflow vulnerability (CVE‑2026‑3542) in Chrome’s asm.js parser that can be triggered by malformed Wasm modules was reported; no PoC, exploit, or patch details were mentioned.

    000221.1K
    4.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Exploit

    CVE-2026-3542 in Chrome's V8 AsmJS parser corrupts WebAssembly opcode streams, bypassing the Ubercage sandbox entirely to reach arbitrary code execution from a single bug. Key findings: - CVE-2026-3542, patched March 3 2026, lives in AsmJsParser::ValidateHeapAccess(). The heap_access_shift_position_ attribute is instance-level state shared across all recursive parse calls. A nested shift expression like HEAP32[1 << (n >> 2)] causes ShiftExpression() to recurse, overwriting that position with a stale offset. When DeleteCodeAfter() truncates the opcode stream using that stale value, subsequent opcodes are left misaligned and later emitted immediates become orphaned opcodes the decoder executes unchecked. - The Ubercage bypass is structural, not incidental. AsmJS-generated opcodes skip ValidationTag::validate entirely because V8 trusts its own parser output. An attacker who controls the corrupted stream can inject opcodes like kExprCallRef or kExprStructGet with no type-safety checks, treating arbitrary 64-bit values on the stack as addresses. This gives out-of-sandbox read/write from a single memory-corruption primitive. - Exploit chain: spray TypeDefinition structs on the canonical type zone so a cross-module struct type lands adjacent to the AsmJS module's type vector. Use kExprI64Const to place a crafted 64-bit address on the stack, then kExprStructGet/kExprStructSet for arbitrary read/write. #DFIR_Radar

    Post summary

    Chrome's V8 AsmJS parser vulnerability CVE-2026-3542 corrupts WebAssembly opcode streams, bypassing the Ubercage sandbox for arbitrary code execution. The text outlines a detailed exploit chain and notes the issue was patched on March 3, 2026.

    10001227
    1.7K followersView on X
  • İmam Gazali@boo8ow1923
    Active Exploitation

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The notice lists multiple high‑risk CVEs, notes evidence of active exploitation for certain zero‑day vulnerabilities, and provides specific patch guidance for affected platforms.

    0100071
    48 followersView on X
  • とれとれたまたま!@ejGyLgtl1l34519
    Disclosure

    ・CVE-2026-3540:Inappropriate implementation in WebAudio(High) ・CVE-2026-3541:Inappropriate implementation in CSS(High) ・CVE-2026-3542:Inappropriate implementation in WebAssembly(High) ・CVE-2026-3543:Inappropriate implementation in V8(High)

    Post summary

    This brief notice lists four newly disclosed high‑severity CVEs affecting WebAudio, CSS, WebAssembly, and V8, detailing their inappropriate implementations.

    1000042
    134 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3542 Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML… https://www.cve.org/CVERecord?id=CVE-2026-3542

    Post summary

    The text is a brief disclosure of CVE-2026-3542, describing an out‑of‑bounds memory access issue in Google Chrome's WebAssembly implementation, with no mention of PoC, exploit code, patches, or active exploitation.

    00010200
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclousre

    CVE-2026-3542 Out-of-Bounds Memory Access Vulnerability in Google Chrome... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3542 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet references CVE-2026-3542, noting an out‑of‑bounds memory access issue in Chrome, but provides only a link to the vulnerability page without any PoC, exploit details, or patch information.

    0000060
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3542 Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML… https://www.cve.org/CVERecord?id=CVE-2026-3542 ----- Traducción: CVE-2026-3542 Imp… http://infoflow.cloud`

    Post summary

    CVE-2026-3542 is an out-of-bounds memory access vulnerability in Chrome’s WebAssembly implementation affecting versions prior to 145.0.7632.159, disclosed via a brief description but lacking a PoC, exploit, or patch reference.

    0000038
    56 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more