CVE-2026-3537 is a critical heap corruption vulnerability in Google Chrome on Android, specifically affecting the PowerVR component prior to version 145.0.7632.159. A remote attacker can exploit this object lifecycle issue by crafting a malicious HTML page. With a CVSS score of 8.8 (HIGH), this vulnerability allows for high impact to confidentiality, integrity, and availability, requiring user interaction but with low attack complexity. There is currently no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code available. However, the vulnerability has garnered significant community discussion and media coverage, indicating awareness and concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 145.0.7632.159, < 145.0.7632.159CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 145.0.7632.159CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.