
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3062 is an out-of-bounds read and write vulnerability in the Tint component of Google Chrome, allowing attackers to trigger memory access violations through malicious web content. It was reported by researcher "cinzinga" on February 11, 2026, and publicly disclosed by Google on February 23, 2026, when Chrome version 145.0.7632.116 was released to address it. The vulnerability affects all Google Chrome versions prior to 145.0.7632.116 (Linux) and 145.0.7632.117 (Windows/Mac), as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 9.8 (Critical) (Chrome Releases, Microsoft MSRC, Feedly).
The vulnerability is rooted in improper memory boundary enforcement within Chrome's Tint graphics/theming component, classified as CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write). An attacker can craft malicious web content that, when processed by the Tint component, causes the browser to read from or write to memory locations outside the intended buffer boundaries. The attack vector is network-based, requires no privileges and no user interaction beyond visiting a malicious page, and has low attack complexity. A public proof-of-concept exploit chain has been published on GitHub (Chrome Releases, Feedly).
Successful exploitation can result in complete compromise of confidentiality, integrity, and availability of the affected system, including arbitrary code execution in the context of the Chrome renderer process, information disclosure via out-of-bounds memory reads, and application crashes causing denial of service. The vulnerability's network-based attack vector with no user interaction requirement means any user visiting a malicious website with a vulnerable Chrome version is at risk. Depending on sandbox escape capabilities, exploitation could potentially enable lateral movement or persistent access to the underlying host (Feedly, Chrome Releases).
chrome.exe / chrome on Linux/Mac) spawning unexpected child processes such as cmd.exe, powershell.exe, /bin/sh, or curl; abnormal memory usage spikes in Chrome renderer processes.Google has released a patch in Chrome version 145.0.7632.116 for Linux and 145.0.7632.116/117 for Windows and Mac — all users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome) (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding update from Microsoft (Microsoft MSRC). Linux distribution users should apply Chromium updates from their respective package managers (Debian, Fedora, openSUSE, etc. have all issued advisories). As an interim measure, organizations can consider blocking access to untrusted websites or restricting Chrome usage until patching is complete, and should prioritize patching given the public PoC availability and critical CVSS score.
Google issued an emergency stable channel update on February 23, 2026, describing the fix as addressing three high-severity vulnerabilities including CVE-2026-3062 (Chrome Releases). Multiple security news outlets including CyberSecurityNews, GBHackers, Forbes, PCWorld, and eSecurity Planet covered the emergency update, emphasizing the urgency of patching given the high severity and public PoC availability. Forbes specifically highlighted the browser danger in a dedicated article titled "Chrome 145 Security Update Decision: Google Confirms Browser Danger." The security community broadly recommended immediate updates, with Tenable and Qualys rapidly releasing detection plugins for the vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."