LeakyCreds
NewInstant webhook alerts now available β€” notified within seconds of any credential detection.Learn more β†’

CVE-2026-3909 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: March 13, 2026

Google Chrome - Out of Bounds Write

Published: March 13, 2026Updated: March 13, 2026KEVRemote Exploitable

Overview

Google Chrome < 146.0.7680.75 contains an out of bounds write caused by improper memory handling in Skia, letting remote attackers perform out of bounds memory access via crafted HTML pages.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 444.3%(Probability of exploitation in next 30 days)

Impact

Remote attackers can perform out of bounds memory access, potentially leading to memory corruption or code execution.

Mitigation

Update to version 146.0.7680.75 or later.

Social Media Activity(1 post)

π”Έπ•Ÿπ• π•Ÿπ•ͺπ•žπ• π•¦π•€ :verified:
π”Έπ•Ÿπ• π•Ÿπ•ͺπ•žπ• π•¦π•€ :verified:
@youranonnewsirc
Mar 24, 2026

Global cybersecurity alerts include active exploitation of Chrome Zero-Days (CVE-2026-3909/3910) and a Quest KACE SMA flaw for credential harvesting. Advanced threats like Android haptic keyloggers and deepfake identity fraud are emerging. Geopolitically, Persian Gulf tensions remain high, while the US announced a new cyber strategy to defend companies from foreign adversaries. In tech, NVIDIA Nemotron 3 Super is now on Amazon Bedrock. #Cybersecurity #GeopoliticalNews #TechBrief

View original post

Details

CVE ID
CVE-2026-3909
Severity
High
CVSS Score
8.8
Type
out_of_bounds_rw
Status
confirmed
EPSS
444.3%
Social Posts
1

CWE

  • CWE-787

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Score

444.3%Probability of exploitation in the next 30 days