CVE-2026-3537
vulnerability analysis and mitigation

Overview

CVE-2026-3537 is a critical object lifecycle issue in the PowerVR graphics driver component of Google Chrome on Android, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. The vulnerability was reported by Zhihua Yao of KunLun Lab on January 8, 2026, and publicly disclosed on March 4, 2026, as part of Chrome's stable channel update to version 145.0.7632.159. It affects all versions of Google Chrome on Android prior to 145.0.7632.159; Microsoft Edge (Chromium-based) is also listed as an affected product. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).

Technical details

The root cause is an object lifecycle mismanagement (CWE-1091: Use of Object without Invoking Destructor Method) in the PowerVR GPU driver integration within Chrome on Android, which can result in an out-of-bounds write (CWE-787) through heap corruption. The attack vector is network-based: an attacker hosts a crafted HTML page that, when visited by a victim using a vulnerable Chrome for Android version, triggers improper handling of GPU-related objects in the PowerVR subsystem. No special privileges are required on the attacker's side, but user interaction (visiting the malicious page) is necessary. The Chromium issue tracker entry is referenced as bug 474266014, though full technical details remain restricted pending broad user patching (Chrome Releases).

Impact

Successful exploitation can result in heap corruption leading to arbitrary code execution or application crashes on affected Android devices, with high impact to confidentiality, integrity, and availability. An attacker who achieves code execution in the Chrome renderer context could potentially access sensitive data stored or processed by the browser, install malware, or pivot to further compromise the device depending on sandbox escape capabilities. The vulnerability is limited to Chrome on Android devices with PowerVR GPU hardware (Chrome Releases, Feedly).

Mitigation and workarounds

Google has patched this vulnerability in Chrome for Android version 145.0.7632.159, released on March 3, 2026. Users should immediately update Chrome on all Android devices to version 145.0.7632.159 or later via the Google Play Store, and ensure auto-update is enabled. Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory. No configuration-based workaround is available; upgrading is the only remediation (Chrome Releases, Microsoft MSRC).

Community reactions

The update was covered by multiple security news outlets including Forbes, CyberSecurityNews, GBHackers, Heise, and PCWorld, which highlighted the emergency nature of the Chrome update addressing three critical vulnerabilities including CVE-2026-3537. Security community discussion noted the $32,000 bounty awarded to the KunLun Lab researcher as indicative of the vulnerability's severity. Downstream Linux distributions (Debian, Fedora, openSUSE, SUSE) and Palo Alto Networks (PAN-SA-2026-0004) and Splunk (SVD-2026-0512) also issued advisories incorporating this CVE as part of their Chromium-based component updates (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management