Vulnerabilities & Exploits
ChromeOS LTS Update Addresses Three High Vulnerabilities The release includes high-severity fixes for CVE-2026-3545 (navigation), CVE-2026-3541 (CSS), and CVE-2026-3542 (WebAssembly).
1 source · Mar 27
CVE-2026-3545 NVD KEV
CVSS 9.6 CRITICAL: insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. EPSS 0.4% (31st percentile). Microsoft patch: Release Notes.
CVE-2026-3542 NVD KEV
CVSS 8.8 HIGH: inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 0.4% (28th percentile). Microsoft patch: Release Notes.
CVE-2026-3541 NVD KEV
CVSS 8.8 HIGH: inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. EPSS 0.3% (17th percentile). Microsoft patch: Release Notes.
Timeline Sources Mar 27 Google Chrome Releases
Long Term Support Channel Update for ChromeOS
A new LTC version 144.0.7559.247 (Platform Version: 16503.79.0 ), is being rolled out for most ChromeOS devices.
original Mar 25 Google Chrome Releases
Stable Channel Update for ChromeOS / ChromeOS Flex
The ChromeOS Stable channel is being updated to OS version 16581.42.0 (Browser version 146.0.7680.169 ) for most ChromeOS devices.
original Mar 24 Google Chrome Releases
Stable Channel Update for Desktop
The Stable channel has been updated to 146.0.7680.164/165 for Windows/Mac and 146.0.7680.164 for Linux, which will roll out over the comin...
original Part of the PlainSec briefing for 2026-03-14
Every edition of this story: ChromeOS LTS Update Addresses Three High Vulnerabilities
More from today
Vulnerabilities & Exploits
ChromeOS LTS Update Addresses Three High Vulnerabilities The release includes high-severity fixes for CVE-2026-3545 (navigation), CVE-2026-3541 (CSS), and CVE-2026-3542 (WebAssembly).
1 source · Mar 27
CVE-2026-3545 NVD KEV
CVSS 9.6 CRITICAL: insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. EPSS 0.4% (31st percentile). Microsoft patch: Release Notes.
CVE-2026-3542 NVD KEV
CVSS 8.8 HIGH: inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 0.4% (28th percentile). Microsoft patch: Release Notes.
CVE-2026-3541 NVD KEV
CVSS 8.8 HIGH: inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. EPSS 0.3% (17th percentile). Microsoft patch: Release Notes.
Timeline Sources Mar 27 Google Chrome Releases
Long Term Support Channel Update for ChromeOS
A new LTC version 144.0.7559.247 (Platform Version: 16503.79.0 ), is being rolled out for most ChromeOS devices.
original Mar 25 Google Chrome Releases
Stable Channel Update for ChromeOS / ChromeOS Flex
The ChromeOS Stable channel is being updated to OS version 16581.42.0 (Browser version 146.0.7680.169 ) for most ChromeOS devices.
original Mar 24 Google Chrome Releases
Stable Channel Update for Desktop
The Stable channel has been updated to 146.0.7680.164/165 for Windows/Mac and 146.0.7680.164 for Linux, which will roll out over the comin...
original Part of the PlainSec briefing for 2026-03-14
Every edition of this story: ChromeOS LTS Update Addresses Three High Vulnerabilities
More from today