
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3061 is an out-of-bounds read vulnerability in the Media component of Google Chrome, classified as High severity. It was reported by security researcher Luke Francis on February 9, 2026, and publicly disclosed on February 23, 2026, when Google released Chrome version 145.0.7632.116 to address it. All Google Chrome versions prior to 145.0.7632.116 (Linux) and 145.0.7632.116/117 (Windows/Mac) are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's Media component, where insufficient bounds checking allows memory to be read beyond the intended buffer boundaries. An attacker can exploit this remotely over the network without requiring any privileges or user interaction, making it particularly dangerous. The attack maps to CAPEC-540 (Overread Buffers), where crafted media content processed by the browser triggers the out-of-bounds read condition. Bug details remain restricted by Google pending broad user adoption of the patch (Chrome Releases).
Successful exploitation enables information disclosure by allowing attackers to read sensitive data from process memory, with high confidentiality and availability impact. Because no user interaction or privileges are required and the attack vector is network-based, a remote attacker could potentially read memory contents from a victim's Chrome process, exposing sensitive data such as credentials, session tokens, or other in-memory information. When chained with additional vulnerabilities, this flaw could contribute to full browser compromise or code execution (Feedly).
Google has patched this vulnerability in Chrome version 145.0.7632.116 for Linux and 145.0.7632.116/117 for Windows and Mac, released on February 23, 2026. Microsoft Edge (Chromium-based) users should also apply the corresponding Microsoft security update. Organizations should prioritize updating all Chrome installations immediately given the high CVSS score (9.1) and the lack of exploitation barriers (no authentication or user interaction required). No configuration-based workarounds have been published; updating to the patched version is the only recommended remediation (Chrome Releases, Microsoft MSRC).
The vulnerability was part of an emergency Chrome update that patched three High-severity flaws simultaneously, prompting broad media coverage. Security outlets including CyberSecurityNews, GBHackers, Forbes, PCWorld, and SecurityOnline.info reported on the update, characterizing it as an urgent patch requiring immediate browser restarts. The Hacker News included it in their weekly recap alongside other critical CVEs. No significant researcher controversy or unusual community sentiment was noted beyond standard patch urgency advisories (CyberSecurityNews, Forbes, The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."