CVE-2026-3926 is a high-severity out-of-bounds read vulnerability in the V8 JavaScript engine of Google Chrome, affecting versions prior to 146.0.7680.71 on Apple, Google, Linux, and Microsoft platforms. Rated with a CVSS score of 8.8 (High), this flaw allows a remote attacker to achieve high confidentiality, integrity, and availability impact by enticing a user to visit a crafted HTML page. The attack requires low complexity and no special privileges, but does necessitate user interaction. Currently, there is no evidence of active exploitation, nor is public exploit code available in common databases like Metasploit or ExploitDB, though it has received some community discussion and media attention regarding security updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.71, < 146.0.7680.71CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.71CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.