
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3541 is an "Inappropriate implementation in CSS" vulnerability in Google Chrome that allows a remote attacker to perform an out-of-bounds memory read via a crafted HTML page. It was reported by researcher Syn4pse on February 16, 2026 (Chromium issue 484811719), and publicly disclosed on March 4, 2026 alongside the release of Chrome 145.0.7632.159. All versions of Google Chrome prior to 145.0.7632.159 (Linux) and 145.0.7632.160 (Windows/Mac) are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The root cause is an improper access control flaw (CWE-284) stemming from an inappropriate implementation in Chrome's CSS parsing engine. By crafting a malicious HTML page with specially constructed CSS, a remote attacker can trigger an out-of-bounds memory read in the browser process. Exploitation requires user interaction — specifically, a victim must visit or be redirected to the attacker-controlled page — but no authentication or elevated privileges are needed. The Chromium bug tracker entry (issue 484811719) remains restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation can result in information disclosure through unintended memory exposure, potentially leaking sensitive data held in browser memory such as credentials, session tokens, or other in-memory content. While the primary impact is a memory read (confidentiality), the CVSS score reflects high impacts across confidentiality, integrity, and availability, suggesting the vulnerability may be chainable with other exploits to achieve broader compromise including code execution. The scope is limited to the browser sandbox, but memory disclosure primitives are commonly leveraged as stepping stones in multi-stage browser exploit chains (Chrome Releases, Microsoft MSRC).
Google has released a patch in Chrome stable channel version 145.0.7632.159 for Linux and 145.0.7632.160 for Windows and Mac. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update that incorporates this fix. Organizations should enforce automatic browser updates or require users to update within a defined timeframe. No configuration-based workaround is available; upgrading to the patched version is the only remediation (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a broader Chrome emergency update that patched 10 security issues, including three Critical-rated CVEs, prompting coverage from multiple security outlets. Security news sites including CyberSecurityNews, GBHackers, SecurityOnline, and BleepingComputer covered the release, characterizing it as an emergency update given the severity of the bundled fixes. The SANS Internet Storm Center (ISC) also noted the update in diary entry 32782. The Zero Day Initiative included it in their March 2026 security update review (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."