Vulnerability Details CVE-2026-3537
Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.3%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-3537
-
cpe:2.3:a:google:chrome:38.0.2125.101
-
cpe:2.3:a:google:chrome:40.0.2214.109
-
cpe:2.3:a:google:chrome:40.0.2214.89
-
cpe:2.3:a:google:chrome:42.0.2311.107
-
cpe:2.3:a:google:chrome:54.0.2840.68
-
cpe:2.3:a:google:chrome:83.0.4103.106
-
-
cpe:2.3:o:linux:linux_kernel:-
-
cpe:2.3:o:microsoft:windows:-