PT-2026-23053 · Google+1 · Google Chrome+1
Qymag1C
·
Published
2026-02-17
·
Updated
2026-05-15
·
CVE-2026-3542
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 145.0.7632.159
Description
An improper implementation in WebAssembly in Google Chrome prior to version 145.0.7632.159 allows a remote attacker to perform out-of-bounds memory access via a crafted HTML page. The issue resides within the WebAssembly component, specifically related to the
asm.js and asm parser functionalities when handling invalid WebAssembly modules. This can lead to a heap-buffer-overflow in the ShiftExpression function.Recommendations
Update Google Chrome to version 145.0.7632.159 or later.
Fix
DoS
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Red Os