CVE-2026-3909 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: March 13, 2026
Google Chrome - Out of Bounds Write
Overview
Google Chrome < 146.0.7680.75 contains an out of bounds write caused by improper memory handling in Skia, letting remote attackers perform out of bounds memory access via crafted HTML pages.
Severity & Score
Impact
Remote attackers can perform out of bounds memory access, potentially leading to memory corruption or code execution.
Mitigation
Update to version 146.0.7680.75 or later.
References
Social Media Activity(9 posts)
đ CVE-2026-3909 - High (8.8) Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) đ https://www.thehackerwire.com/vulnerability/CVE-2026-3909/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postđ¨ [CISA-2026:0313] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0313) CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. â ď¸ CVE-2026-3909 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-3909) - Name: Google Skia Out-of-Bounds Write Vulnerability - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. - Known To Be Used in Ransomware Campaigns? Unknown - Vendor: Google - Product: Skia - Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html#:~:text=Google%20is%20aware ; https://nvd.nist.gov/vuln/detail/CVE-2026-3909 â ď¸ CVE-2026-3910 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-3910) - Name: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. - Known To Be Used in Ransomware Campaigns? Unknown - Vendor: Google - Product: Chromium V8 - Notes: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3910 #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260313 #cisa20260313 #cve_2026_3909 #cve_2026_3910 #cve20263909 #cve20263910
View original postCVE ID: CVE-2026-3909 Vendor: Google Product: Skia Date Added: 2026-03-13 Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html#:~:text=Google%20is%20aware ; https://nvd.nist.gov/vuln/detail/CVE-2026-3909 CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3909
View original postCISA has updated the KEV catalogue. - CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-3909 - CVE-2026-3910: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-3910 #CISA #Google #infosec #vulnerability
View original postđ CVE-2026-3909 - High (8.8) Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) đ https://www.thehackerwire.com/vulnerability/CVE-2026-3909/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postđ¨ [CISA-2026:0313] CISA Adds 2 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0313) CISA has added 2 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise. â ď¸ CVE-2026-3909 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-3909) - Name: Google Skia Out-of-Bounds Write Vulnerability - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. - Known To Be Used in Ransomware Campaigns? Unknown - Vendor: Google - Product: Skia - Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html#:~:text=Google%20is%20aware ; https://nvd.nist.gov/vuln/detail/CVE-2026-3909 â ď¸ CVE-2026-3910 (https://secdb.nttzen.cloud/cve/detail/CVE-2026-3910) - Name: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability - Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. - Known To Be Used in Ransomware Campaigns? Unknown - Vendor: Google - Product: Chromium V8 - Notes: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3910 #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260313 #cisa20260313 #cve_2026_3909 #cve_2026_3910 #cve20263909 #cve20263910
View original postCVE ID: CVE-2026-3909 Vendor: Google Product: Skia Date Added: 2026-03-13 Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html#:~:text=Google%20is%20aware ; https://nvd.nist.gov/vuln/detail/CVE-2026-3909 CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3909
View original postCISA has updated the KEV catalogue. - CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-3909 - CVE-2026-3910: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-3910 #CISA #Google #infosec #vulnerability
View original postTrivalent 145.0.7632.75-442755 released: https://github.com/secureblue/Trivalent/releases/tag/146.0.7680.75-443342 Google is aware that exploits for both CVE-2026-3909 & CVE-2026-3910 exist in the wild. https://github.com/secureblue/Trivalent/releases/tag/146.0.7680.75-443342
View original postRelated Resources
Details
- CVE ID
- CVE-2026-3909
- Severity
- High
- CVSS Score
- 8.8
- Type
- out_of_bounds_rw
- Status
- confirmed
- EPSS
- 6.8%
- Social Posts
- 9
CWE
- CWE-787
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H