


Perceptive Security
SOC/SIEM Consultancy

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (C…
Published:
12 maart 2026 om 23:00:00
Alert date:
13 maart 2026 om 20:06:20
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-3909 is a high-severity out-of-bounds write vulnerability in the Skia graphics library component of Google Chrome. The vulnerability affects Chrome versions prior to 146.0.7680.75 and allows remote attackers to perform out-of-bounds memory access through specially crafted HTML pages. This vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaw represents a significant security risk as it can be triggered remotely through malicious web content without user interaction beyond visiting a compromised webpage. Google has addressed this vulnerability in Chrome version 146.0.7680.75 and later releases.
Technical details
Mitigation steps:
Affected products:
Google Chrome
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3909
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
https://issues.chromium.org/issues/491421267
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3909
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
