
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3538 is a Critical integer overflow vulnerability in the Skia graphics engine within Google Chrome, allowing a remote attacker to potentially perform out-of-bounds memory access via a crafted HTML page. It was reported by Symeon Paraschoudis on February 17, 2026, and publicly disclosed on March 3–4, 2026, when Google released Chrome 145.0.7632.159 to address it. Affected products include Google Chrome prior to version 145.0.7632.159 and Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, Microsoft MSRC).
The root cause is an integer overflow (CWE-191: Integer Underflow/Wraparound) in Chrome's Skia 2D graphics library, which can lead to out-of-bounds memory access when processing specially crafted graphical content embedded in an HTML page. The attack vector is network-based and requires user interaction — specifically, a victim must visit or be redirected to a malicious web page. No special privileges are required for the attacker. The Chromium issue tracker references bug ID 484983991, though full technical details remain restricted pending broad patch deployment (Chrome Release).
Successful exploitation could result in out-of-bounds memory read or write operations within the Chrome renderer process, potentially leading to information disclosure, data corruption, or denial of service. In a worst-case scenario, an attacker could leverage this memory corruption primitive to achieve arbitrary code execution within the browser's sandbox. The vulnerability affects all major desktop platforms (Windows, macOS, Linux) running unpatched Chrome versions, as well as Chromium-based browsers such as Microsoft Edge (Chrome Release, Microsoft MSRC).
Google released the fix in Chrome stable channel version 145.0.7632.159 (Linux) and 145.0.7632.159/160 (Windows/Mac), published on March 3, 2026. Users should update Chrome immediately via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or enable automatic updates. Microsoft Edge users should apply the corresponding Chromium-based Edge update via the Microsoft Security Response Center advisory. Organizations should enforce automatic browser updates via policy and consider restricting access to untrusted websites as a temporary defense-in-depth measure (Chrome Release, Microsoft MSRC).
The update was covered as part of a broader emergency Chrome release patching 10 vulnerabilities, including three rated Critical. Security outlets including SecurityOnline, CyberSecurityNews, GBHackers, Forbes, Heise, and PCWorld reported on the update, emphasizing the Critical severity of the Skia and ANGLE integer overflow flaws (SecurityOnline, Forbes). The SANS Internet Storm Center and Zero Day Initiative also included this CVE in their March 2026 patch review summaries (SANS ISC, ZDI Blog). Downstream Linux distributions including Debian, Fedora, and openSUSE issued their own Chromium security advisories shortly after the upstream fix.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."