
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3544 is a heap buffer overflow vulnerability in the WebCodecs component of Google Chrome that allows a remote attacker to perform out-of-bounds memory writes via a crafted HTML page. It affects Google Chrome versions prior to 145.0.7632.159 and Microsoft Edge (Chromium-based). The vulnerability was reported by an anonymous researcher (handle: c6eed09fc8b174b0f3eebedcceb1e792) on 2026-02-19 and patched on 2026-03-03 with the stable channel update. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), rooted in insufficient bounds checking within Chrome's WebCodecs API — a browser interface for low-level access to media encoding and decoding. An attacker can craft a malicious HTML page that triggers the WebCodecs component to write beyond the bounds of an allocated heap buffer, potentially corrupting adjacent memory. Exploitation requires user interaction (visiting a malicious page) but no authentication or special privileges. The Chromium issue tracker references bug ID 485683110 for this vulnerability (Chrome Releases).
Successful exploitation can result in arbitrary out-of-bounds memory writes, which may lead to remote code execution, data corruption, or full system compromise within the context of the Chrome renderer process. All three security pillars — confidentiality, integrity, and availability — are rated as High impact. If combined with a sandbox escape (such as the co-disclosed CVE-2026-3545), an attacker could potentially achieve full browser compromise and lateral movement beyond the sandboxed renderer (Chrome Releases).
VideoDecoder, AudioDecoder, or related interfaces) with specially crafted input parameters designed to trigger a heap buffer overflow in the underlying C++ implementation.cmd.exe, powershell.exe, /bin/sh, curl) that are not typical browser subprocesses; Chrome renderer crashes or abnormal termination events.Google has released a patch in Chrome stable channel version 145.0.7632.159 (Linux) and 145.0.7632.159/160 (Windows/Mac). Microsoft has also issued an update for Edge (Chromium-based) addressing this CVE. Users and administrators should immediately update Chrome to version 145.0.7632.159 or later and ensure automatic updates are enabled across the organization. As a temporary workaround where patching is not immediately possible, consider restricting access to untrusted or unknown websites and monitoring for suspicious browser behavior (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a broader emergency Chrome update patching 10 security issues, which received notable coverage from cybersecurity media outlets including CyberSecurityNews, GBHackers, SecurityOnline, and BleepingComputer, with several describing it as a critical emergency update (SecurityOnline, CyberSecurityNews). The Hacker Wire published a dedicated write-up on the WebCodecs heap overflow (The Hacker Wire). SANS ISC and Zero Day Initiative also included it in their March 2026 security update reviews. Community sentiment on social media (Bluesky, Mastodon) reflected urgency around patching given the co-disclosure of multiple High and Critical Chrome vulnerabilities in the same update.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."