Vulnerabilità ed exploit

ChromeOS LTS Risolve Tre Vulnerabilità ad Alta Gravità

Include correzioni ad alta gravità per CVE-2026-3545 (Navigation), CVE-2026-3541 (CSS) e CVE-2026-3542 (WebAssembly).

1 fonte · 27 mar

CVE-2026-3542

NVD KEV

CVSS 8.8 HIGH: inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 0.4% (33º percentile). Patch Microsoft: Release Notes.

CVE-2026-3545

NVD KEV

CVSS 9.6 CRITICAL: insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. EPSS 0.3% (23º percentile). Patch Microsoft: Release Notes.

CVE-2026-3541

NVD KEV

CVSS 8.8 HIGH: inappropriate implementation in CSS in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. EPSS 0.3% (22º percentile). Patch Microsoft: Release Notes.

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-14

Every edition of this story: ChromeOS LTS Risolve Tre Vulnerabilità ad Alta Gravità

Altro da oggi