
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3539 is an object lifecycle issue in Google Chrome's DevTools component that can lead to heap corruption via a crafted Chrome Extension. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-02-12, it was publicly disclosed on March 3–4, 2026, as part of a 10-fix Chrome stable channel update. The vulnerability affects Google Chrome versions prior to 145.0.7632.159, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The root cause is classified as CWE-1091 (Use of Object without Invoking Destructor Method), an object lifecycle management flaw within Chrome's DevTools subsystem. The vulnerability arises when DevTools fails to properly manage the lifecycle of certain objects, leaving memory in a corrupted state that an attacker can leverage for heap corruption. Exploitation requires user interaction: an attacker must convince a target to install a malicious Chrome Extension, which then triggers the faulty object lifecycle behavior through crafted extension logic. The Chromium bug tracker references issue 483853098, though full technical details remain restricted pending broad user patching (Chrome Releases).
Successful exploitation can result in heap corruption enabling arbitrary code execution with the privileges of the Chrome browser process, affecting confidentiality, integrity, and availability of the system. An attacker achieving code execution within the browser process could access sensitive data stored or processed by the browser, install persistent malware, or use the compromised browser as a pivot point for further attacks on the local system or network. The scope is limited to the browser process (sandbox escape would require a separate vulnerability), but the high-privilege browser context still represents a significant risk (Feedly).
cmd.exe, powershell.exe, bash).%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ on Windows); suspicious files written by the Chrome process to unexpected directories.chrome.exe.Update Google Chrome to version 145.0.7632.159 (Linux) or 145.0.7632.159/160 (Windows/Mac) or later, which contains the fix for this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update as well (Microsoft MSRC). As a workaround, organizations should enforce Chrome extension policies (e.g., via Group Policy or Chrome Enterprise) to restrict extension installation to an approved allowlist, and educate users to avoid installing extensions from untrusted sources. Debian, openSUSE, Fedora, and other Linux distributions have also released updated Chromium packages addressing this issue.
The vulnerability was covered by several security news outlets as part of Google's emergency Chrome update addressing 10 security issues, including three Critical-rated flaws (SecurityOnline, CyberSecurityNews). The SANS Internet Storm Center noted the update in its diary (SANS ISC). The Zero Day Initiative included it in their March 2026 security update review (ZDI Blog). Community reaction was generally focused on the broader Chrome update rather than this specific CVE, given the absence of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."