← Vulnerability feed

Vulnerability record · CVE-2011-3026 · published 16 February 2012

CVE-2011-3026: libpng integer overflow in Chrome and Apple products

Google · Chrome

An integer overflow in libpng, as used in Google Chrome before 17.0.963.56, can be triggered by unknown vectors that cause an integer truncation. The flaw affects Chrome as well as Apple and SUSE products that bundle libpng, and it can lead to denial of service or possibly other unspecified impact. Because libpng is a widely embedded image library, the exposure extends beyond the browser itself.

6.8 CVSS 2.0 Medium EPSS 73% · top 0.6% CWE-190 · Integer overflow
6.8CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
26References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.

AV:N/AC:M/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable without authentication in a widely embedded library, and EPSS is very high at the 99.4th percentile, though the CVSS 2.0 score is only 6.8 and no KEV listing exists.

What it is

An integer overflow in libpng, as used in Google Chrome before 17.0.963.56, can be triggered by unknown vectors that cause an integer truncation. The flaw affects Chrome as well as Apple and SUSE products that bundle libpng, and it can lead to denial of service or possibly other unspecified impact. Because libpng is a widely embedded image library, the exposure extends beyond the browser itself.

Impact

An attacker can cause a denial of service, and the record leaves open the possibility of unspecified other impact such as memory corruption. No confirmed code execution or data disclosure is stated.

Attack surface

The CVSS vector AV:N/AC:M/Au:N indicates remote reachability with no authentication, but medium access complexity and the description's 'unknown vectors' mean the exact delivery path is not specified. User interaction is not stated in the record, though a browser or image-parsing context is implied by the affected products.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.73347 (99.4th percentile), and one Chromium issue reference is tagged 'Exploit'. No public exploit code or in-the-wild activity is confirmed by the record.

What to do

  • Upgrade Google Chrome to 17.0.963.56 or later, and apply the corresponding Apple and SUSE libpng updates referenced in the advisories.
  • Patch or replace any other software that statically links or bundles libpng, since the library is embedded in many products.
  • Where immediate patching is not possible, restrict processing of untrusted PNG images and limit exposure of affected applications.
  • Track vendor advisories for libpng updates and verify library versions across the environment.

Detection

  • Monitor for crashes or abnormal termination in Chrome, image parsers, or libpng-linked applications, which may indicate malformed PNG input.
  • Inspect network and proxy logs for PNG files delivered from untrusted or unusual sources to browser and image-processing endpoints.
  • Check installed versions of Chrome, macOS, iOS, and SUSE packages against the fixed releases named in the advisories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://code.google.com/p/chromium/issues/detail?id=112822 ExploitVendor Advisory
http://googlechromereleases.blogspot.com/2012/02/chrome-stable-update.html Release NotesVendor Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00020.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00023.html Mailing ListThird Party Advisory
http://secunia.com/advisories/48016 Not Applicable
http://secunia.com/advisories/48110 Not Applicable
http://secunia.com/advisories/49660 Not Applicable
http://security.gentoo.org/glsa/glsa-201206-15.xml Third Party Advisory
http://support.apple.com/kb/HT5501 Third Party Advisory
http://support.apple.com/kb/HT5503 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15032 Third Party Advisory
http://code.google.com/p/chromium/issues/detail?id=112822 ExploitVendor Advisory
http://googlechromereleases.blogspot.com/2012/02/chrome-stable-update.html Release NotesVendor Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00003.html Mailing ListThird Party Advisory
http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00020.html Mailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00023.html Mailing ListThird Party Advisory
http://secunia.com/advisories/48016 Not Applicable
http://secunia.com/advisories/48110 Not Applicable
http://secunia.com/advisories/49660 Not Applicable
http://security.gentoo.org/glsa/glsa-201206-15.xml Third Party Advisory
http://support.apple.com/kb/HT5501 Third Party Advisory
http://support.apple.com/kb/HT5503 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15032 Third Party Advisory

Track CVE-2011-3026 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-43300Apple iOS, iPadOS and macOS out-of-bounds write via malicious imageAn out-of-bounds write in Apple iOS, iPadOS and macOS is triggered when processing a malicious image file, causing memory corruption. Apple states th…KEVEPSS 22%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2025-24085Apple iOS, iPadOS, macOS, tvOS, visionOS, watchOS Use-After-Free Privilege EscalationA use-after-free flaw in Apple's operating systems was fixed through improved memory management in iOS 18.3, iPadOS 18.3 and 17.7.6, macOS Sequoia 15…KEVEPSS 18%analysed9.8CVE-2025-10585Google Chrome V8 type confusion enables heap corruptionChrome's V8 JavaScript engine contains a type confusion flaw (CWE-843) that can lead to heap corruption when processing a crafted HTML page. It affec…KEVEPSS 5.4%analysed9.8CVE-2025-31200Apple OS media parsing memory corruption allows code executionA memory corruption flaw in Apple's audio stream processing was fixed with improved bounds checking across iOS, iPadOS, macOS, tvOS, visionOS and wat…KEVEPSS 19%analysed9.8CVE-2025-31201Apple OS Pointer Authentication bypass via arbitrary read/writeApple removed vulnerable code that allowed an attacker holding arbitrary read and write capability to bypass Pointer Authentication across iOS, iPadO…KEVEPSS 14%analysed9.8CVE-2022-22587Apple iOS, iPadOS and macOS kernel memory corruption via out-of-bounds writeAn out-of-bounds write (CWE-787) in Apple iOS, iPadOS and macOS is caused by insufficient input validation and can corrupt memory. Apple states it is…KEVEPSS 12%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed

Source: NIST National Vulnerability Database (record CVE-2011-3026), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.