Exodus Intelligence disclosed CVE-2026-3542, a Chrome vulnerability in V8’s AsmJS-to-WebAssembly pipeline that allowed attackers to break out of the Ubercage sandbox and achieve arbitrary code execution. The flaw stemmed from shared parser state used to track heap-access shift operations: nested shift expressions could overwrite truncation metadata, causing V8 to generate a stale, misaligned WebAssembly opcode stream. Because AsmJS-generated opcodes were treated as trusted, the malformed stream bypassed normal WebAssembly validation and enabled execution of unintended opcodes.
The write-up shows how the bug could be turned into arbitrary read/write by abusing missing validation on cross-module type access for struct opcodes, leaking the trusted cage base through WasmTrustedInstanceData, and overwriting a WebAssembly jump table to seize control of execution. The research echoes earlier browser JIT exploitation work such as Google Project Zero’s analysis of CVE-2020-9802 in WebKit JavaScriptCore, where compiler optimization errors also produced out-of-bounds access and exploit primitives despite modern mitigations. Google patched CVE-2026-3542 in Chrome on 3 March 2026.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-22, Exodus Intelligence published a detailed write-up on CVE-2026-3542, explaining how the V8 AsmJS parser bug could bypass validation, achieve arbitrary read/write, leak the trusted cage base, and overwrite a WebAssembly jump table for code execution.
Exodus Intelligence reported that Chrome patched CVE-2026-3542 on 2026-03-03. The vulnerability was caused by flawed shared-state handling in V8’s AsmJS parser, enabling malformed trusted WebAssembly opcode streams and exploitation outside the Ubercage sandbox.
On 2020-09-01, Google Project Zero published an analysis of CVE-2020-9802 and demonstrated a proof-of-concept exploit against Mobile Safari on iOS 13.4.1 and Safari 13.1 on macOS 10.15.4. The write-up detailed how the bug could corrupt JSArray metadata and be turned into addrof and fakeobj primitives.
Project Zero reported that Apple fixed mitigation bypasses CVE-2020-9870 and CVE-2020-9910 in iOS 13.6. These bypasses were relevant to the broader exploitation context discussed alongside CVE-2020-9802.
Apple fixed the JavaScriptCore JIT vulnerability CVE-2020-9802 in iOS 13.5, according to Project Zero's write-up. The flaw involved incorrect Common Subexpression Elimination handling of ArithNegate operations and could lead to out-of-bounds access in WebKit’s JavaScript engine.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
blog.exodusintel.com
Open sourcechromereleases.googleblog.com
Open sourcegoogleprojectzero.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.