LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-3916 - Vulnerability Analysis

CriticalCVSS: 9.6

Last Updated: March 13, 2026

Google Chrome - Out of Bounds Read

Published: March 11, 2026Updated: March 13, 2026Remote Exploitable

Overview

Google Chrome < 146.0.7680.71 contains an out of bounds read in Web Speech, letting remote attackers potentially perform sandbox escape via crafted HTML page, exploit requires victim to load crafted page.

Severity & Score

Severity: Critical
CVSS Score: 9.6
EPSS Score: 6.2%(Probability of exploitation in next 30 days)

Impact

Remote attackers can escape the sandbox, potentially compromising the browser and underlying system.

Mitigation

Update to version 146.0.7680.71 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 13, 2026

šŸ”“ CVE-2026-3916 - Critical (9.6) Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-3916/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 13, 2026

šŸ”“ CVE-2026-3916 - Critical (9.6) Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-3916/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-3916
Severity
Critical
CVSS Score
9.6
Type
out_of_bounds_rw
Status
confirmed
EPSS
6.2%
Social Posts
2

CWE

  • CWE-125

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS Score

6.2%Probability of exploitation in the next 30 days