CVE-2026-3545 is a critical sandbox escape vulnerability in Chrome's Navigation component with a CVSS score of 9.6. It could be exploited to trick the browser into reading local files from the user's system. The flaw was discovered via an agent harness leveraging Google's Gemini models and remained undetected for over 13 years. It was patched by Google in March 2026.