Cyber Cookie mascotCyber Cookie
Menu ▾
CVE-2026-3545
criticalCVSS 9.8

Google Chrome (versions prior to Chrome 145)

Google Chrome is the world's most widely used web browser, installed on billions of devices for everyday browsing, work, and personal use.

Reported in Issue #51Brinks Home Hit by Vishing Gang

Root Cause

Chrome runs web content inside a sandboxed renderer process, a walled-off environment designed to keep untrusted code away from your system. The Navigation component failed to properly validate data passed between that renderer and the browser's core process. This meant a compromised renderer could trick the browser into reading local files it should never be able to access.

Attack Vector

An attacker crafts a malicious HTML page and lures the target into visiting it. The page exploits the validation gap in the Navigation component, escaping the sandbox and gaining access to local files on the device.

Recommended Actions

  1. Open Chrome, go to Settings → Help → About Google Chrome, and confirm you are on version 145 or later.
  2. Enable automatic updates if they are not already on.
  3. If you manage a fleet of devices, prioritise this update across all Chrome installations this week.