CVE-2026-3909
CVSS Score
8.8
EPSS Score
4.4%
EPSS Percentile
89th
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
| CWE | CWE-787 |
| Vendor | |
| Product | chrome |
| Ecosystems | |
| Industries | Technology |
| Published | Mar 12, 2026 |
| Last Updated | Mar 24, 2026 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for google chrome
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-3909.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google / Chrome
146.0.7680.75 < 146.0.7680.75