Google’s AI agent built on the Gemini model identified CVE-2026-3545, a critical sandbox escape vulnerability in Chrome’s Navigation component with a CVSS score of 9.8 out of 10. The faulty code had been present in Chrome since 2013, representing thirteen years of potential exposure before being patched in version 145 released in May 2026. Chrome set patching records in 2026, with versions 149 and 150 together fixing 1,072 security bugs, surpassing the cumulative total of the previous 23 stable Chrome releases. Google is piloting twice-weekly security releases and developing automated vulnerability detection and patch generation. This discovery carries major implications for crypto security: wallets, nodes, and decentralized applications running through browser extensions or web interfaces depend on Chrome’s security model.
Source: Read the original article

