CVE-2026-3545Disclosure(apple / chrome)

MEDIUMCVSS 9.6 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-07-31); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Mentions · 2026-03-10: 2Mentions · 2026-07-31: 3Mentions · 2026-08-02: 1Active Exploitation · 2026-03-10: 1Patch / Workaround · 2026-03-10: 2Patch / Workaround · 2026-07-31: 2Patch / Workaround · 2026-08-02: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 2Technical Details · 2026-07-31: 3Technical Details · 2026-08-02: 103-0403-0503-0803-1007-3108-02
Signal classification4 categories
Disclosure
550.0%
Patch
330.0%
General
110.0%
Active Exploitation
110.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-042
Disclosure2
2026-03-051
Disclosure1
2026-03-081
General1
2026-03-102
Active Exploitation1Patch1
2026-07-313
Disclosure2Patch1
2026-08-021
Patch1
Full discourse10 posts
  • Center for Security Studies and Cyber Defense@CSSCD_AU
    Disclosure

    Google revealed that its AI-powered vulnerability discovery system uncovered a Chrome sandbox escape vulnerability that had remained hidden for 13 years. CVE-2026-3545 was one of more that 1,800 vulnerabilities patched in Chrome this year. https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace https://t.co/wIo2cqJpya

    Post summary

    Google’s AI-powered discovery system exposed a 13‑year‑old Chrome sandbox escape (CVE‑2026‑3545), which is one of 1,800 flaws now patched, highlighting ongoing vulnerability detection efforts.

    02041114
    89 followersView on X
  • ProtAAPP - Protege las AAPP@ProtAAPP
    Patch

    Google ha corregido 1,072 errores de seguridad en Chrome 149 y 150, superando los 23 anteriores. En la versión 151, se solucionaron 370 fallos, 349 reportados por Google. Destaca la CVE-2026-3545, una grave vulnerabilidad que permite leer archivos… https://thehackernews.com/2026/07/three-recent-chrome-releases-fix-1442.html https://t.co/sWB4RqiSZu

    Post summary

    Google patched the severe CVE‑2026‑3545 vulnerability that allowed file reads in Chrome 151, adding 370 fixes to the release.

    02020312
    8.3K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Chrome 149-151 fixed 1,442 flaws total, including 7 critical issues. A sandbox escape flaw, CVE-2026-3545, could enable local file access as Google speeds up releases and patching. #Chrome #CVE2026 #Google https://www.hendryadrian.com/three-recent-chrome-releases-fix-1442-flaws-more-than-prior-23-updates-combined/

    Post summary

    Google released Chrome 149‑151 patches that fix 1,442 flaws, including CVE‑2026‑3545, a sandbox‑escape vulnerability enabling potential local file access, with no indication of active exploitation or PoC.

    00040323
    4.9K followersView on X
  • XQRTX@XQOPTRX
    Disclosure

    🧠 Google AI Discovers 13-Year-Old Chrome Sandbox Escape Google says its AI-powered vulnerability research system discovered a critical Chrome flaw that had remained undetected for approximately 13 years. Tracked as CVE-2026-3545, the vulnerability could have allowed a compromised renderer to access local files. Google is now using AI to identify, validate, triage and generate candidate fixes for browser vulnerabilities. 📰 Source: SecurityWeek #GoogleChrome #AISecurity #VulnerabilityResearch #CyberSecurity

    Post summary

    Google AI uncovered a long‑undetected Chrome sandbox escape (CVE‑2026‑3545) that could let a compromised renderer read local files, but no exploit details, PoC, or patch information are provided.

    0001048
    8 followersView on X
  • İmam Gazali@boo8ow1923
    Active Exploitation

    İşte güncel ve yamasız kritik güvenlik zafiyetlerinin CVE listesi, önem derecesine göre sıralanmış şekilde: ## Kritik Zafiyetler (CVSS 10.0 - En Yüksek Risk) - **Cisco Secure Firewall ürünleri**: Mart 2026 güncellemesinde 48 güvenlik açığı giderildi, bunlardan 2 tanesi CVSS 10.0 seviyesinde kritik açıklardır. Bu açıklar saldırganlara sistem kontrolü vermektedir.^4^ ## Sıfır Gün Açıkları (Aktif İstismar Riski) - **CVE-2026-21385**: Android için - sınırlı ve hedefli istismar edildiğine dair işaretler bulunan sıfır gün açığı^1^ - **CVE-2026-21510**: Windows Shell güvenlik özelliği atlama açığı^3^ - **CVE-2026-21513**: MSHTML Framework güvenlik özelliği atlama açığı^3^ - **CVE-2026-21514**: Microsoft Word güvenlik özelliği atlama açığı^3^ - **CVE-2026-21519**: Desktop Window Manager yetki yükseltme açığı^3^ - **CVE-2026-21533**: Remote Desktop Services yetki yükseltme açığı^3^ - **CVE-2026-21525**: Remote Access Connection Manager hizmet aksatma açığı^3^ ## Google Chrome Kritik Açıkları - **CVE-2026-3536**: ANGLE'da tamsayı taşması (Kritik)^10^ - **CVE-2026-3537**: PowerVR'da nesne yaşam döngüsü sorunu (Kritik)^10^ - **CVE-2026-3538**: Skia'da tamsayı taşması (Kritik)^10^ ## Yüksek Önemli Açıklar - **CVE-2026-3539**: DevTools'da nesne yaşam döngüsü sorunu (Yüksek)^10^ - **CVE-2026-3540**: WebAudio'da uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3541**: CSS'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3542**: WebAssembly'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3543**: V8'de uygunsuz implementasyon (Yüksek)^10^ - **CVE-2026-3544**: WebCodecs'da heap buffer overflow (Yüksek)^10^ - **CVE-2026-3545**: Navigasyonda yetersiz veri doğrulama (Yüksek)^10^ ## Güncelleme Önerileri - **Windows 11**: KB5077181 (25H2/24H2) ve KB5075941 (23H2) güncellemeleri ile 6 sıfır gün açığı kapatıldı^3^ - **Android**: 2026-03-05 güvenlik yama seviyesi veya üzeri tüm açıkları giderir^1,2^ - **Google Chrome**: En son sürüme güncelleme yapılması kritik açıklar için zorunludur^1^ - **Cisco ürünleri**: Mart 2026 paket güvenlik güncellemesinin uygulanması gerekir^4^ Bu zafiyetler arasında özellikle sıfır gün açıkları ve CVSS 10.0 seviyesindeki açıklar en yüksek riski taşımaktadır ve acil olarak yamanması gerekmektedir.

    Post summary

    The post enumerates a series of high‑risk zero‑day CVEs with indications of active exploitation, while also providing patch references and urging immediate update of affected systems.

    0100071
    48 followersView on X
  • とれとれたまたま!@ejGyLgtl1l34519
    General

    ・CVE-2026-3544:Heap buffer overflow in WebCodecs(High) ・CVE-2026-3545:Insufficient data validation in Navigation(High)  ※深刻度の評価は、4段階中最高の「Critical」が3件、上から2番目の「High」が7件。今のところ悪用の報告はないようだが、できるだけ早い対応を心掛けたい。

    Post summary

    A brief report lists two high‑severity CVEs (Heap buffer overflow and insufficient data validation) with no known exploitation or available patches, urging prompt mitigation.

    1000042
    134 followersView on X
  • CSIRT-CAN@CSIRTCAN
    Patch

    ➡️La vulnerabilidad de @Google Chrome (CVE-2026-3545) Permite que datos manipulados en una página HTML maliciosa no sean correctamente verificados: Actualizar Google Chrome Aplicar actualizaciones automáticas del navegador. #Ciberseguridad #GoogleChrome #Ciberinteligencia

    Post summary

    The tweet highlights Chrome CVE‑2026‑3545, where manipulated HTML data bypasses verification, and recommends users update to the latest Chrome version to address the issue.

    0000049
    66 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3545 Chrome Sandbox Escape via Malicious HTML Page in Versions Prior to 145.0.7632.159 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3545

    Post summary

    The post provides a disclosure of CVE-2026-3545, detailing a Chrome sandbox escape vulnerability with affected version information, but offers no PoC, exploit code, or update details.

    0000056
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3545 Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML… https://www.cve.org/CVERecord?id=CVE-2026-3545 ----- Traducción: CVE-2026-3545 Val… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑3545, describing an insufficient data validation flaw in Chrome that could allow a sandbox escape through crafted HTML and links to the CVE record for further details.

    0000036
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3545 Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML… https://www.cve.org/CVERecord?id=CVE-2026-3545

    Post summary

    The sentence announces CVE-2026-3545, detailing its technical nature as a sandbox escape via crafted HTML, without providing PoC, exploit, or patch information.

    00000175
    56.6K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more