
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3545 is a high-severity insufficient data validation vulnerability in the Navigation component of Google Chrome that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It affects Google Chrome versions prior to 145.0.7632.159 (Linux) and 145.0.7632.160 (Windows/Mac), as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Google's internal security team on February 24, 2026, and patched on March 3, 2026, with public disclosure on March 4, 2026. It carries a CVSS v3.1 base score of 9.6 (Critical) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-20 (Improper Input Validation) and resides in Chrome's Navigation subsystem, where insufficient validation of data allows attacker-controlled input to influence navigation behavior in an unsafe manner. The attack vector is network-based, requiring user interaction (visiting a crafted HTML page), but has low attack complexity and requires no privileges. The changed scope in the CVSS vector indicates that successful exploitation can affect components beyond the vulnerable browser process — specifically, it enables a sandbox escape, breaking out of Chrome's renderer sandbox to interact with the underlying operating system. The Chromium issue tracker entry (ID 487383169) is currently restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation allows a remote attacker to escape Chrome's sandbox, potentially achieving arbitrary code execution with the privileges of the Chrome process on the host system. This results in high confidentiality, integrity, and availability impacts — an attacker could access sensitive user data, modify system files, install malware, or render the system unavailable. The scope change means the impact extends beyond the browser itself to the underlying operating system, enabling potential lateral movement or persistent compromise of the affected host (Chrome Releases, Microsoft MSRC).
Google released the fix in Chrome stable channel version 145.0.7632.159 for Linux and 145.0.7632.160 for Windows/Mac on March 3, 2026; users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update addressing CVE-2026-3545 (Microsoft MSRC). Linux distribution users (Debian, Fedora, openSUSE, SUSE) should apply the Chromium package updates provided by their respective distribution security teams. As a temporary measure, organizations may consider restricting access to untrusted web content or enforcing browser update policies via enterprise management tools. No configuration-based workaround is available that fully mitigates the vulnerability without patching (Chrome Releases).
Google issued an emergency Chrome update covering 10 security fixes, with CVE-2026-3545 among the high-severity issues, prompting coverage from multiple security news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and CyberPress, all characterizing it as a critical emergency update. The Zero Day Initiative's March 2026 security update review and SANS ISC diary also noted the release. Microsoft acknowledged the vulnerability's impact on Edge Chromium in its March 2026 Patch Tuesday advisory. Community and social media reactions were consistent with standard high-severity browser patch urgency, with no unusual controversy or researcher dispute noted (Chrome Releases, Microsoft MSRC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."