CVE-2026-3542: High Inappropriate implementation in WebAssembly
Chromium: CVE-2026-3542 Inappropriate implementation in WebAssembly
Other sources
Inappropriate implementation in WebAssembly in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3542?
CVE-2026-3542 has a high severity level due to the potential for remote attackers to exploit out of bounds memory access.
How do I fix CVE-2026-3542?
To fix CVE-2026-3542, update Google Chrome to version 145.0.7632.159 or later.
What types of systems are affected by CVE-2026-3542?
CVE-2026-3542 affects Google Chrome versions prior to 145.0.7632.159 on all platforms.
What can an attacker achieve by exploiting CVE-2026-3542?
An attacker exploiting CVE-2026-3542 can perform out of bounds memory access, potentially leading to arbitrary code execution.
Is there a workaround for CVE-2026-3542?
There is no specific workaround recommended for CVE-2026-3542; the best mitigation is to apply the security update.