CVE-2026-3544Disclosure(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-05); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-04: 2Mentions · 2026-03-05: 4Mentions · 2026-03-08: 1Mentions · 2026-03-10: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 3Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 103-0403-0503-0803-10
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-054
Disclosure3Patch1
2026-03-081
General1
2026-03-101
Patch1
Full discourse8 posts
  • xvonfers@xvonfers
    Patch

    (CVE-2026-3544)[485683110][media][webcodecs]Hep-BoF in WebCodecs BackgroundReadback -> OOBW https://chromium-review.googlesource.com/c/chromium/src/+/7596362 https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html Test: https://chromium-review.googlesource.com/c/chromium/src/+/5667032 Reported by c6eed09fc8b174b0f3eebedcceb1e792

    Post summary

    CVE-2026-3544 is a Hep‑buffer overflow in WebCodecs BackgroundReadback, leading to an out‑of‑bounds write, and a patch has been released in the stable channel update.

    0001761.4K
    4.9K followersView on X
  • İmam Gazali@boo8ow1923
    Patch

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The post lists numerous high‑risk CVEs, highlights indications of active exploitation, and provides explicit patch/workaround guidance for Windows, Android, Chrome, and Cisco products.

    0100071
    48 followersView on X
  • とれとれたまたま!@ejGyLgtl1l34519
    General

    ・CVE-2026-3544:Heap buffer overflow in WebCodecs(High) ・CVE-2026-3545:Insufficient data validation in Navigation(High)  ※深刻度の評価は、4段階中最高の「Critical」が3件、上から2番目の「High」が7件。今のところ悪用の報告はないようだが、できるだけ早い対応を心掛けたい。

    Post summary

    The post lists two high‑severity CVEs with brief technical descriptions, notes that no exploitation has yet been reported, but urges early remediation.

    1000042
    134 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3544 - High Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severi... https://www.thehackerwire.com/vulnerability/CVE-2026-3544/ https://t.co/iUn2O0nENe

    Post summary

    The tweet announces a heap buffer overflow in Chrome's WebCodecs, detailing the affected version and attack method, without mentioning a PoC, exploit tool, or patch.

    0000049
    124 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Google Chrome (CVE-2026-3544) https://vuldb.com/?id.348837

    Post summary

    The tweet announces the disclosure of vulnerability CVE-2026-3544 for Google Chrome, noting an increase in severity, but provides no further technical or exploitation details.

    0000090
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3544 Heap Buffer Overflow in Google Chrome WebCodecs Enables Remote Memory Corruption https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3544

    Post summary

    The post announces CVE‑2026‑3544— a heap buffer overflow in Google Chrome’s WebCodecs module that can cause remote memory corruption, linking to a vulnerability report.

    0000074
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3544 Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (… https://www.cve.org/CVERecord?id=CVE-2026-3544 ----- Traducción: CVE-2026-3544 des… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑3544, detailing a heap buffer overflow in Chrome’s WebCodecs that allows remote memory writes via a crafted HTML page.

    0000038
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3544 Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (… https://www.cve.org/CVERecord?id=CVE-2026-3544

    Post summary

    The text reports a discovered heap buffer overflow vulnerability in WebCodecs (CVE-2026-3544) that can be triggered by a crafted HTML page, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00000194
    56.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more