CVE-2026-3542
8.8Google · Chrome
An inappropriate implementation in the WebAssembly component of Google Chrome allows remote attackers to perform out of bounds memory access via a crafted HTML page.
Executive summary
A high-severity memory corruption vulnerability in Google Chrome WebAssembly allows remote attackers to execute unauthorized actions via malicious web content.
Vulnerability
The vulnerability is an inappropriate implementation flaw within the WebAssembly engine that permits out of bounds memory access. An unauthenticated remote attacker can trigger this condition by enticing a user to visit a specially crafted HTML page.
Business impact
The exploitation of this vulnerability could lead to significant security compromises, including unauthorized information disclosure, data integrity loss, or potential system instability. With a CVSS score of 8.8, this flaw represents a high risk to organizational security, as browser-based attacks are a common vector for initial system compromise and lateral movement within corporate environments.
Remediation
Immediate Action: Update Google Chrome to version 145.0.7632.159 or later immediately to incorporate the provided security patches.
Proactive Monitoring: Review web proxy and endpoint detection logs for unusual browser activity or crashes that might indicate attempts to exploit memory corruption vulnerabilities.
Compensating Controls: While browser-level patches are the primary defense, deploying robust endpoint security solutions can help detect and block malicious web-based payloads.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the widespread use of Google Chrome, this vulnerability poses a significant risk to user endpoints. Organizations should prioritize the deployment of the browser update across all workstations to ensure protection against potential memory corruption attacks.