CVE-2026-3536: Integer overflow in ANGLE
Chromium: CVE-2026-3536 Integer overflow in ANGLE
Other sources
Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-3536?
CVE-2026-3536 has a critical severity rating due to its potential to allow remote attackers to perform out-of-bounds memory access.
How do I fix CVE-2026-3536?
To fix CVE-2026-3536, update Google Chrome to version 145.0.7632.159 or later.
What causes CVE-2026-3536?
CVE-2026-3536 is caused by an integer overflow vulnerability in the ANGLE component of Chromium.
Which software is affected by CVE-2026-3536?
CVE-2026-3536 affects Google Chrome versions prior to 145.0.7632.159.
Can CVE-2026-3536 be exploited in any environment?
Yes, CVE-2026-3536 can be exploited via a crafted HTML page in any environment running the affected versions of Google Chrome.