Description
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
In plain language
AI Act nowCVE-2026-3909 is a Chrome/Edge/Chromium graphics bug that can crash the browser or potentially let an attacker take advantage of memory when you view a specially crafted web page; update your browser to the fixed version if you use these browsers and they can be reached through normal web browsing.
CVE-2026-3909 is an out-of-bounds write in Skia in Google Chrome/Edge that a remote attacker can trigger via a crafted HTML page, requiring user interaction; it is listed in CISA KEV (added 2026-03-13) with a remediation due date of 2026-03-27.
What to do now
- Check whether your Google Chrome or Microsoft Edge is running a version earlier than 146.0.7680.75.
- Update to Google Chrome 146.0.7680.75 or later (preferred) or 146.0.7680.80 or later if that is your available track.
- After updating, verify you are no longer on an earlier Chrome build by reopening the browser “About” page.
- If you cannot update immediately, limit exposure by avoiding unknown links and restricting access to untrusted websites until patching is possible.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- В браузере Chrome исправили шестую 0-day-уязвимость в этом годуru-ru·Хакер (xakep.ru)·
- Google patches actively exploited Chrome zero-day (CVE-2026-85046)en-us·Help Net Security· Exploited Chrome zero-day
- Google warns of new Chrome zero-day flaw exploited in attacksen-us·BleepingComputer· Exploited Chrome zero-day
- Google Patches 6th Chrome Zero-Day of 2026en-us·SecurityWeek· Exploited Chrome zero-day
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Dayen·The Hacker News· Exploited Chrome zero-day
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and Moreen·The Hacker News· Exploited Chrome (V8) UNC6240 (ShinyHunters)
- В Chrome исправили уязвимость нулевого дняru-ru·Хакер (xakep.ru)· Exploited Google Chrome (V8 engine) zero-day
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Nowen·The Hacker News· Exploited Google Chrome zero-day
- Google patches new Chrome zero-day flaw exploited in the wilden-us·BleepingComputer· Exploited Google Chrome rce
- Google Patches 5th Chrome Zero-Day Exploited in 2026en-us·SecurityWeek· Exploited Google Chrome rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-3909 and every CVE in our database. Create a free account — no credit card required.
Create Free Account