CVE-2026-3062
vulnerability analysis and mitigation

Overview

CVE-2026-3062 is an out-of-bounds read and write vulnerability in the Tint component of Google Chrome, allowing attackers to trigger memory access violations through malicious web content. It was reported by researcher "cinzinga" on February 11, 2026, and publicly disclosed by Google on February 23, 2026, when Chrome version 145.0.7632.116 was released to address it. The vulnerability affects all Google Chrome versions prior to 145.0.7632.116 (Linux) and 145.0.7632.117 (Windows/Mac), as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 9.8 (Critical) (Chrome Releases, Microsoft MSRC, Feedly).

Technical details

The vulnerability is rooted in improper memory boundary enforcement within Chrome's Tint graphics/theming component, classified as CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write). An attacker can craft malicious web content that, when processed by the Tint component, causes the browser to read from or write to memory locations outside the intended buffer boundaries. The attack vector is network-based, requires no privileges and no user interaction beyond visiting a malicious page, and has low attack complexity. A public proof-of-concept exploit chain has been published on GitHub (Chrome Releases, Feedly).

Impact

Successful exploitation can result in complete compromise of confidentiality, integrity, and availability of the affected system, including arbitrary code execution in the context of the Chrome renderer process, information disclosure via out-of-bounds memory reads, and application crashes causing denial of service. The vulnerability's network-based attack vector with no user interaction requirement means any user visiting a malicious website with a vulnerable Chrome version is at risk. Depending on sandbox escape capabilities, exploitation could potentially enable lateral movement or persistent access to the underlying host (Feedly, Chrome Releases).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 145.0.7632.116/117 using browser fingerprinting techniques or by targeting broad user populations via a malicious or compromised website.
  2. Craft malicious web content: Develop or adapt a payload targeting the Tint component — Chrome's graphics/theming subsystem — that triggers an out-of-bounds read or write when the browser processes specific graphical or UI rendering operations.
  3. Host and deliver payload: Host the malicious page on an attacker-controlled server or inject it into a legitimate site via cross-site scripting or supply chain compromise. Lure the victim to visit the page (e.g., via phishing, malvertising, or watering hole attack).
  4. Trigger memory corruption: When the victim's vulnerable Chrome browser renders the malicious content, the Tint component performs an out-of-bounds memory access, potentially allowing the attacker to leak sensitive memory contents or corrupt heap/stack memory.
  5. Achieve code execution: Leverage the memory corruption primitive (as demonstrated in the public PoC chain on GitHub) to achieve arbitrary code execution within the Chrome renderer sandbox, potentially chaining with a sandbox escape for full system compromise (Chrome Releases, Feedly).

Indicators of compromise

  • Network: Unusual outbound connections from the Chrome process to unknown or suspicious IP addresses/domains following web browsing activity; HTTP requests to domains hosting known exploit infrastructure.
  • Process: Chrome renderer processes (chrome.exe / chrome on Linux/Mac) spawning unexpected child processes such as cmd.exe, powershell.exe, /bin/sh, or curl; abnormal memory usage spikes in Chrome renderer processes.
  • Logs: Browser crash reports or minidumps referencing the Tint component; Windows Event Logs or system logs showing unexpected process creation events originating from Chrome.
  • File System: Unexpected files written to the user's temp directory or Chrome profile directory by the Chrome process; new scheduled tasks, cron jobs, or persistence mechanisms created shortly after browser activity.

Mitigation and workarounds

Google has released a patch in Chrome version 145.0.7632.116 for Linux and 145.0.7632.116/117 for Windows and Mac — all users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome) (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding update from Microsoft (Microsoft MSRC). Linux distribution users should apply Chromium updates from their respective package managers (Debian, Fedora, openSUSE, etc. have all issued advisories). As an interim measure, organizations can consider blocking access to untrusted websites or restricting Chrome usage until patching is complete, and should prioritize patching given the public PoC availability and critical CVSS score.

Community reactions

Google issued an emergency stable channel update on February 23, 2026, describing the fix as addressing three high-severity vulnerabilities including CVE-2026-3062 (Chrome Releases). Multiple security news outlets including CyberSecurityNews, GBHackers, Forbes, PCWorld, and eSecurity Planet covered the emergency update, emphasizing the urgency of patching given the high severity and public PoC availability. Forbes specifically highlighted the browser danger in a dedicated article titled "Chrome 145 Security Update Decision: Google Confirms Browser Danger." The security community broadly recommended immediate updates, with Tenable and Qualys rapidly releasing detection plugins for the vulnerability.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management