Vulnerabilities & Exploits

ChromeOS Long-Term Channel Gets High-Severity Security Update

Google rolled out ChromeOS LTC 144.0.7559.246 to most Long-Term Channel devices. The update includes two high-severity fixes: CVE-2026-3909 (Skia out-of-bounds write) and CVE-2026-3910 (V8 inappropriate implementation). LTS-138 remains on its prior build until April 21, 2026.

1 source · Mar 27

CVE-2026-3545

NVD KEV

CVSS 9.6 CRITICAL: insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. EPSS 0.4% (31st percentile). Microsoft patch: Release Notes.

CVE-2026-3542

NVD KEV

CVSS 8.8 HIGH: inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 0.4% (28th percentile). Microsoft patch: Release Notes.

CVE-2026-3541

NVD KEV

CVSS 8.8 HIGH: inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. EPSS 0.3% (17th percentile). Microsoft patch: Release Notes.

Timeline

Sources

Part of the PlainSec briefing for 2026-03-17

Every edition of this story: ChromeOS Long-Term Channel Gets High-Severity Security Update

More from today