CVE-2026-3545
CRITICAL · 9.6 EPSS 0.3%Real vuln, patched baseline, but chatter is speculation-heavy marketing; no PoC or KEV listing.
What: Insufficient data validation in Chrome navigation prior to v145.0.7632.159 permits sandbox escape via crafted HTML; CVSS 9.6 (CRITICAL), EPSS 0.18%.
Why it matters: Fixed in Chrome 145+. Not KEV-listed. Social chatter focuses heavily on Google's AI-driven detection narrative and speculative "13-year-old flaw" claims rather than exploitation evidence or urgent patching signals. No public PoC or in-the-wild activity reported in posts.
Where it's seen: Bluesky posts dominate, centering on AI detection story and vendor marketing angles. Minimal defender triage signals; mostly clickbait and speculation around detection methodology and oversight risks.
RISK: HIGH — CVSS 9.6 sandbox escape; Chrome already patched; no active exploitation signal evident.
Description
Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- Required
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
Affected versions
- google/chrome
- < 145.0.7632.159
- < 145.0.7632.160
References
- https://issues.chromium.org/issues/487383169 [Issue Tracking, Permissions Required]