CVE-2026-3541
8.8Google · Chrome
A CSS implementation flaw in Google Chrome allows a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Executive summary
A high severity out of bounds memory read vulnerability in Google Chrome poses a significant risk to user data confidentiality and system integrity.
Vulnerability
The vulnerability exists due to an inappropriate implementation within the CSS engine of Google Chrome. This flaw allows an unauthenticated remote attacker to trigger an out of bounds memory read through a specially crafted HTML page.
Business impact
The ability for an attacker to read out of bounds memory can lead to the exposure of sensitive information stored in the browser process memory, including user credentials or session tokens. Given the CVSS score of 8.8, this vulnerability represents a high risk that could facilitate further exploitation or unauthorized access to user accounts.
Remediation
Immediate Action: Update Google Chrome to the latest stable version beyond 145.0.7632.159 as provided in the official Google Chrome security release.
Proactive Monitoring: Security teams should monitor browser crash logs and endpoint security telemetry for indications of unusual memory access patterns or unexpected browser process terminations.
Compensating Controls: While browser updates are the primary defense, deploying endpoint protection solutions that detect malicious script execution can help mitigate the risk of a crafted page being processed.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
This vulnerability carries a high severity rating and should be prioritized for patching across all managed endpoints. Organizations must ensure that the automatic update mechanisms for Google Chrome are functioning correctly to protect users from potential remote exploitation via malicious web content.