Vulnerability · NVD
CVE-2026-3537
CVE-2026-3537, high severity (CVSS 8.8): 1 tracked app concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 8.8
- Exploitation
- 0.4 %
- Tracked apps
- 1
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Show raw CVSS vector
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Observed affected builds (24)
143.0.7499.146 142.0.7444.158 139.0.7258.160 138.0.7204.179 138.0.7204.157 138.0.7204.63 136.0.7103.88 132.0.6834.123 130.0.6723.102 129.0.6668.100 123.0.6312.40 120.0.6099.144 119.0.6045.163 118.0.5993.111 114.0.5735.196 114.0.5735.131 109.0.5414.117 103.0.5060.70 102.0.5005.98 90.0.4430.91 88.0.4324.181 88.0.4324.152 87.0.4280.141 70.0.3538.80
NVD references 4 distinct products for this CVE : only those tracked by Scout (mobile and desktop catalog apps) are listed above. Libraries, servers and out-of-scope products do not appear here. Full list on NVD ↗
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome Android
|
Android | <145.0.7632.159 | cpe:2.3:a:google:chrome:*:*:*:*:*:android:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.