CVE-2026-3543

8.8

Google · Chrome

Google Chrome contains an inappropriate implementation in the V8 engine, potentially allowing a remote attacker to perform out of bounds memory access via a crafted HTML page.

Executive summary

A high-severity memory safety vulnerability in Google Chrome allows remote attackers to perform out of bounds memory access via crafted web content.

Vulnerability

The V8 JavaScript engine contains an inappropriate implementation flaw that permits an unauthenticated remote attacker to trigger out of bounds memory access. This vulnerability is typically triggered when a user navigates to a malicious HTML page.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for significant impact on system integrity and confidentiality. Successful exploitation could allow an attacker to read or manipulate sensitive memory, potentially leading to arbitrary code execution or a complete compromise of the browser process. Such outcomes pose a high risk of data exfiltration and unauthorized access to corporate resources.

Remediation

Immediate Action: Update Google Chrome to version 145.0.7632.159 or later immediately to incorporate the necessary security patches for the V8 engine.

Proactive Monitoring: Review security logs for unusual browser activity or frequent crashes that might indicate attempts to trigger memory corruption vulnerabilities.

Compensating Controls: Ensure that endpoint protection software is active and that users are utilizing the latest browser security features, such as site isolation, to minimize the impact of potential memory corruption attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity of this memory safety issue, organizations should prioritize the deployment of the Google Chrome update across all endpoints. Promptly addressing this vulnerability is critical to protecting users from remote memory-based attacks that bypass standard application security controls.

More Google CVEs

Sources