CVE-2026-3544

8.8

Google · Chrome

A heap buffer overflow in the Google Chrome WebCodecs component allows a remote attacker to trigger an out of bounds memory write via a crafted HTML page.

Executive summary

A heap buffer overflow vulnerability in Google Chrome allows remote attackers to execute arbitrary code via crafted HTML content, posing a high risk to user systems.

Vulnerability

This is a heap buffer overflow (CWE-122) in the WebCodecs component, which can be triggered by an unauthenticated remote attacker through a maliciously crafted HTML page. The vulnerability involves an out of bounds memory write, which typically leads to application crashes or remote code execution.

Business impact

The potential for remote code execution presents a significant threat to organizational security, as it could allow attackers to gain control over user workstations, exfiltrate sensitive data, or install persistent malware. With a CVSS score of 8.8, this vulnerability is categorized as High severity, reflecting the impact on confidentiality, integrity, and availability. Failure to remediate this flaw could result in widespread system compromise and potential data breaches.

Remediation

Immediate Action: Update Google Chrome to version 145.0.7632.159 or later immediately to incorporate the vendor security patch.

Proactive Monitoring: Monitor endpoint security logs for unusual process execution patterns or unexpected browser crashes that may indicate exploitation attempts.

Compensating Controls: Use browser isolation technologies or endpoint protection platforms capable of detecting and blocking malicious memory operations within web browsers.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity of this heap buffer overflow and the potential for remote exploitation, all organizations should prioritize the deployment of the latest Google Chrome updates. Administrators must ensure that all endpoints are patched to version 145.0.7632.159 or newer to eliminate this attack vector. Continuous monitoring of browser activity remains a recommended best practice for maintaining a resilient security posture.

More Google CVEs

Sources