CVE-2026-3538
vulnerability analysis and mitigation

Overview

CVE-2026-3538 is a Critical integer overflow vulnerability in the Skia graphics engine within Google Chrome, allowing a remote attacker to potentially perform out-of-bounds memory access via a crafted HTML page. It was reported by Symeon Paraschoudis on February 17, 2026, and publicly disclosed on March 3–4, 2026, when Google released Chrome 145.0.7632.159 to address it. Affected products include Google Chrome prior to version 145.0.7632.159 and Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, Microsoft MSRC).

Technical details

The root cause is an integer overflow (CWE-191: Integer Underflow/Wraparound) in Chrome's Skia 2D graphics library, which can lead to out-of-bounds memory access when processing specially crafted graphical content embedded in an HTML page. The attack vector is network-based and requires user interaction — specifically, a victim must visit or be redirected to a malicious web page. No special privileges are required for the attacker. The Chromium issue tracker references bug ID 484983991, though full technical details remain restricted pending broad patch deployment (Chrome Release).

Impact

Successful exploitation could result in out-of-bounds memory read or write operations within the Chrome renderer process, potentially leading to information disclosure, data corruption, or denial of service. In a worst-case scenario, an attacker could leverage this memory corruption primitive to achieve arbitrary code execution within the browser's sandbox. The vulnerability affects all major desktop platforms (Windows, macOS, Linux) running unpatched Chrome versions, as well as Chromium-based browsers such as Microsoft Edge (Chrome Release, Microsoft MSRC).

Mitigation and workarounds

Google released the fix in Chrome stable channel version 145.0.7632.159 (Linux) and 145.0.7632.159/160 (Windows/Mac), published on March 3, 2026. Users should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or enable automatic updates. Microsoft Edge users should apply the corresponding Chromium-based Edge update via the Microsoft Security Response Center advisory. Organizations should enforce automatic browser updates via policy and consider restricting access to untrusted websites as a temporary defense-in-depth measure (Chrome Release, Microsoft MSRC).

Community reactions

The update was covered as part of a broader emergency Chrome release patching 10 vulnerabilities, including three rated Critical. Security outlets including SecurityOnline, CyberSecurityNews, GBHackers, Forbes, Heise, and PCWorld reported on the update, emphasizing the Critical severity of the Skia and ANGLE integer overflow flaws (SecurityOnline, Forbes). The SANS Internet Storm Center and Zero Day Initiative also included this CVE in their March 2026 patch review summaries (SANS ISC, ZDI Blog). Downstream Linux distributions including Debian, Fedora, and openSUSE issued their own Chromium security advisories shortly after the upstream fix.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management