Vulnerability record · CVE-2011-3026 · published 16 February 2012
CVE-2011-3026: libpng integer overflow in Chrome and Apple products
Google · Chrome
An integer overflow in libpng, as used in Google Chrome before 17.0.963.56, can be triggered by unknown vectors that cause an integer truncation. The flaw affects Chrome as well as Apple and SUSE products that bundle libpng, and it can lead to denial of service or possibly other unspecified impact. Because libpng is a widely embedded image library, the exposure extends beyond the browser itself.
Description
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely reachable without authentication in a widely embedded library, and EPSS is very high at the 99.4th percentile, though the CVSS 2.0 score is only 6.8 and no KEV listing exists.
What it is
An integer overflow in libpng, as used in Google Chrome before 17.0.963.56, can be triggered by unknown vectors that cause an integer truncation. The flaw affects Chrome as well as Apple and SUSE products that bundle libpng, and it can lead to denial of service or possibly other unspecified impact. Because libpng is a widely embedded image library, the exposure extends beyond the browser itself.
Impact
An attacker can cause a denial of service, and the record leaves open the possibility of unspecified other impact such as memory corruption. No confirmed code execution or data disclosure is stated.
Attack surface
The CVSS vector AV:N/AC:M/Au:N indicates remote reachability with no authentication, but medium access complexity and the description's 'unknown vectors' mean the exact delivery path is not specified. User interaction is not stated in the record, though a browser or image-parsing context is implied by the affected products.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.73347 (99.4th percentile), and one Chromium issue reference is tagged 'Exploit'. No public exploit code or in-the-wild activity is confirmed by the record.
What to do
- Upgrade Google Chrome to 17.0.963.56 or later, and apply the corresponding Apple and SUSE libpng updates referenced in the advisories.
- Patch or replace any other software that statically links or bundles libpng, since the library is embedded in many products.
- Where immediate patching is not possible, restrict processing of untrusted PNG images and limit exposure of affected applications.
- Track vendor advisories for libpng updates and verify library versions across the environment.
Detection
- Monitor for crashes or abnormal termination in Chrome, image parsers, or libpng-linked applications, which may indicate malformed PNG input.
- Inspect network and proxy logs for PNG files delivered from untrusted or unusual sources to browser and image-processing endpoints.
- Check installed versions of Chrome, macOS, iOS, and SUSE packages against the fixed releases named in the advisories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3026 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3026), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.