CVE-2026-3909 is a high-severity out-of-bounds write vulnerability in Google Chrome's Skia component, affecting various platforms including Apple, Google, Linux, and Microsoft. This flaw allows a remote attacker to achieve out-of-bounds memory access via a specially crafted HTML page, requiring user interaction but with low attack complexity. Rated with a CVSS score of 8.8 (High), it poses a significant risk to confidentiality, integrity, and availability. Critically, this vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered substantial community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.75, < 146.0.7680.75CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.80CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.