Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2026/VULN260
_____________________________________________________________________

DATE                : 05/03/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Chrome versions prior to
                                145.0.7632.159/160.

=====================================================================
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop.html
_____________________________________________________________________


Stable Channel Update for Desktop
Tuesday, March 3, 2026

 The Stable channel has been updated to 145.0.7632.159/160 for
Windows/Mac  and 145.0.7632.159 for Linux, which will roll out over
the coming days/weeks. A full list of changes in this build is
available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until
a majority of users are updated with a fix. We will also retain
restrictions if the bug exists in a third party library that other
projects similarly depend on, but haven’t yet fixed.

This update includes 10 security fixes. Please see the Chrome
Security Page for more information.

[$33,000][485622239] Critical CVE-2026-3536: Integer overflow in
ANGLE. Reported by cinzinga on 2026-02-18

[$32,000][474266014] Critical CVE-2026-3537: Object lifecycle
issue in PowerVR. Reported by Zhihua Yao of KunLun Lab on
2026-01-08

[TBD][484983991] Critical CVE-2026-3538: Integer overflow in
Skia. Reported by Symeon Paraschoudis on 2026-02-17

[TBD][483853098] High CVE-2026-3539: Object lifecycle issue in
DevTools. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-02-12

[TBD][484088917] High CVE-2026-3540: Inappropriate implementation
in WebAudio. Reported by Davi Antônio Cruz on 2026-02-14

[TBD][484811719] High CVE-2026-3541: Inappropriate implementation
in CSS. Reported by Syn4pse on 2026-02-16

[TBD][485152421] High CVE-2026-3542: Inappropriate implementation
in WebAssembly. Reported by qymag1c on 2026-02-17

[TBD][485267831] High CVE-2026-3543: Inappropriate implementation
in V8. Reported by qymag1c on 2026-02-18

[TBD][485683110] High CVE-2026-3544: Heap buffer overflow in
WebCodecs. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on
2026-02-19

[TBD][487383169] High CVE-2026-3545: Insufficient data validation
in Navigation. Reported by Google on 2026-02-24

We would also like to thank all security researchers that worked
with us during the development cycle to prevent security bugs
from ever reaching the stable channel.

Many of our security bugs are detected using AddressSanitizer,
MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow
Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here.
If you find a new issue, please let us know by filing a bug.
The community help forum is also a great place to reach out
for help or learn about common issues.


Srinivas Sista

Google Chrome
Share on Twitter Share on Facebook

=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




