CVE-2026-3543Disclosure(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-05); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-03-04: 2Mentions · 2026-03-05: 3Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 103-0403-0503-0603-0803-10
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-053
Disclosure3
2026-03-061
General1
2026-03-081
Disclosure1
2026-03-101
Patch1
Full discourse8 posts
  • QYmag1c@QYmag1c
    General

    Two new Chrome V8 CVEs assigned (CVE-2026-3542 and CVE-2026-3543) 🎯 Big thanks to @bjrjk for the help and guidance! https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html

    Post summary

    The tweet announces two new Chrome V8 CVEs and links to an update page, but it contains no explicit PoC, exploit, active exploitation, patch details, or technical specificity.

    28065263.5K
    75 followersView on X
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-3543)[485267831][ast][parser]Inappropriate implementation(stack overflow) https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html Reported by @QYmag1c

    Post summary

    The text announces CVE-2026-3543, noting it involves an inappropriate implementation leading to a stack overflow, and references a Google Chrome stable channel release, implying patching but without explicit details.

    010531.2K
    4.9K followersView on X
  • İmam Gazali@boo8ow1923
    Patch

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The bulletin lists critical CVEs, highlights evidence of active exploitation for at least one zero‑day, and provides specific patch recommendations for affected platforms.

    0100071
    48 followersView on X
  • とれとれたまたま!@ejGyLgtl1l34519
    Disclosure

    ・CVE-2026-3540:Inappropriate implementation in WebAudio(High) ・CVE-2026-3541:Inappropriate implementation in CSS(High) ・CVE-2026-3542:Inappropriate implementation in WebAssembly(High) ・CVE-2026-3543:Inappropriate implementation in V8(High)

    Post summary

    Four new CVEs are announced for different Chrome components, all marked as High severity, with no further exploitation, Patch, or PoC details provided.

    1000042
    134 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3543 Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted H… https://www.cve.org/CVERecord?id=CVE-2026-3543

    Post summary

    The text reports a CVE affecting Google Chrome’s V8 engine, describing a potential remote out-of-bounds memory access vulnerability, with no PoC, exploit, patch, or evidence of active exploitation presented.

    01000188
    56.6K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-3543) https://vuldb.com/?id.348836

    Post summary

    The message announces a new high‑criticality vulnerability in Google Chrome (CVE-2026-3543) but provides no technical details, PoC, or exploitation information.

    0000094
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3543 Out-of-Bounds Memory Access Vulnerability in Google Chrome V8 Java... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3543 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE-2026-3543, providing a link to more details but offering no evidence of exploitation, patch, or PoC.

    0000069
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3543 Inappropriate implementation in V8 in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted H… https://www.cve.org/CVERecord?id=CVE-2026-3543 ----- Traducción: CVE-2026-3543 Imp… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑3543, a memory‑corruption flaw in Google Chrome’s V8 engine, and provides a link to the CVE record, but does not mention any PoC, exploit code, active exploitation, or patch.

    0000038
    56 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more