Categories: Cyber Security News

Google Issues Emergency Chrome Update to Patch 10 Security Vulnerabilities

Google has rolled out an urgent security patch for Chrome on March 3, 2026, targeting 10 vulnerabilities in the stable channel.

This update version 145.0.7632.159/160 for Windows and macOS, and 145.0.7632.159 for Linux addresses three critical and seven high-severity flaws.

These issues span memory corruption, integer overflows, and implementation errors in core components like graphics engines and V8 JavaScript.

Attackers could exploit them for arbitrary code execution, data leaks, or full system compromise, especially via malicious web content.

The patch deploys gradually to minimize disruption, but Google withholds full technical details until most users update.

This aligns with their 72-hour disclosure policy to thwart rapid weaponization by threat actors. Many flaws were uncovered via fuzzing tools like AddressSanitizer and libFuzzer, highlighting proactive defense in Chrome’s development.

Critical Flaws and CVE Breakdown

Three critical vulnerabilities pose the highest risk, enabling remote code execution without user interaction.

Integer overflows in ANGLE, and Skia could trigger heap corruption during graphics rendering, while a PowerVR lifecycle bug risks use-after-free attacks.

Sponsored
CVE ID Severity Component Vulnerability Type Discoverer / Reward
CVE-2026-3536 Critical ANGLE Integer overflow cinzinga ($33,000)
CVE-2026-3537 Critical PowerVR Object lifecycle issue Zhihua Yao ($32,000)
CVE-2026-3538 Critical Skia Integer overflow Symeon Paraschoudis (TBD)
CVE-2026-3539 High DevTools Object lifecycle issue Zhenpeng (Leo) Lin (TBD)
CVE-2026-3540 High WebAudio Inappropriate implementation Davi Antônio Cruz (TBD)
CVE-2026-3541 High CSS Inappropriate implementation Syn4pse (TBD)
CVE-2026-3542 High WebAssembly Inappropriate implementation qymag1c (TBD)
CVE-2026-3543 High V8 Inappropriate implementation qymag1c (TBD)
CVE-2026-3544 High WebCodecs Heap buffer overflow Anonymous (TBD)
CVE-2026-3545 High Navigation Insufficient data validation Google (Internal)

High-severity issues include heap overflows and validation gaps in WebCodecs and Navigation, potentially aiding phishing or drive-by downloads.

Users should update now: Go to Chrome > Help > About Google Chrome to relaunch with the patch. Enterprises must enforce via group policies or tools like Microsoft Intune, prioritizing endpoints exposed to untrusted sites.

No active exploitation is confirmed, but CVSS scores (likely 9.8+ for criticals) underscore urgency. Map to MITRE ATT&CK T1190 (Exploit Public-Facing Application).

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post Google Issues Emergency Chrome Update to Patch 10 Security Vulnerabilities appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

DJI will pay $30K to the man who accidentally hacked 7,000 Romo robovacs

The DJI Romo robot vacuums. | Image: DJI On Valentine's Day, I brought you a…

10 minutes ago

Magic: The Gathering’s TMNT Turtle Power Deck is Amazing, Here’s Why I Love It

Magic: The Gathering’s crossovers get harder to predict, and the second set of the year…

2 hours ago

The Best Pixar Movies: Ranked From Worst to Best

Pixar's Hoppers, about a young animal rights activist (Piper Curda) who transfers her mind into…

4 hours ago

A Court of Thorns and Roses Book Six and Seven Are Already Up for Preorder

After more than five years since the last book in the series was published, Sarah…

4 hours ago

Truck collision in Belvidere brings down large power line officials say

A giant power line was knocked down Friday evening after a truck crashed into it.

4 hours ago

Flooding forces closure of Caledonia Elementary School

Students at Caledonia Elementary School were sent home Friday morning after heavy rainfall caused flooding…

4 hours ago

This website uses cookies.