Description
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
In plain language
AI Act nowCVE-2026-3910 is a Chrome/Edge browser security bug where a specially crafted web page could let an attacker run code inside the browser’s protected sandbox—if you use these browsers, you should update, because it’s reachable with no login and can be triggered when a user opens the page.
Unauthenticated remote attacker can trigger a sandbox escape/use of a V8 flaw in Google Chrome (and Chromium-based browsers like Microsoft Edge) via a crafted HTML page, resulting in arbitrary code execution inside the browser sandbox; this issue is listed in the CISA KEV set with a mitigation due date.
What to do now
- Check whether your business devices use Google Chrome or Microsoft Edge, and what version they are running.
- Update immediately to the fixed version: Google Chrome 146.0.7680.75 (or newer) on affected devices.
- If you manage Linux desktops/servers: ensure your distro packages for Chrome/Edge are updated to include the fix.
- If you cannot update right away, restrict access to untrusted websites (and tighten browser security settings per your browser/vendor guidance) until patched.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- В браузере Chrome исправили шестую 0-day-уязвимость в этом годуru-ru·Хакер (xakep.ru)·
- Google patches actively exploited Chrome zero-day (CVE-2026-85046)en-us·Help Net Security· Exploited Chrome zero-day
- Google warns of new Chrome zero-day flaw exploited in attacksen-us·BleepingComputer· Exploited Chrome zero-day
- Google Patches 6th Chrome Zero-Day of 2026en-us·SecurityWeek· Exploited Chrome zero-day
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Dayen·The Hacker News· Exploited Chrome zero-day
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and Moreen·The Hacker News· Exploited Chrome (V8) UNC6240 (ShinyHunters)
- В Chrome исправили уязвимость нулевого дняru-ru·Хакер (xakep.ru)· Exploited Google Chrome (V8 engine) zero-day
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Nowen·The Hacker News· Exploited Google Chrome zero-day
- Google patches new Chrome zero-day flaw exploited in the wilden-us·BleepingComputer· Exploited Google Chrome rce
- Google Patches 5th Chrome Zero-Day Exploited in 2026en-us·SecurityWeek· Exploited Google Chrome rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-3910 and every CVE in our database. Create a free account — no credit card required.
Create Free Account