Google Chrome Skia and V8 Vulnerabilities (CVE-2026-3909 & CVE-2026-3910)

Two zero-day vulnerabilities (CVE-2026-3909 and CVE-2026-3910) were identified recently and impacting Google Chrome and Chromium-based browsers.  The vulnerabilities enable a remote unauthenticated attacker to perform out‑of‑bounds memory access (CVE‑2026‑3909) or execute arbitrary code inside the Chrome sandbox (CVE‑2026‑3910) via crafted HTML pages.  Both vulnerabilities are actively exploited in the wild, users are urged to update their browsers to the latest version immediately to mitigate any potential threats.

 

Vulnerability

 

Severity Level

  • High

 

Affected versions

  • Google Chrome prior to 146.0.7680.80 (Windows)
  • Google Chrome prior to 146.0.7680.80 (Linux)
  • Google Chrome prior to 146.0.7680.80 (Mac)
  • Google Chrome prior to 146.0.76380.119 (Android)
  • Microsoft Edge prior to 146.0.3856.59

 

Remediation

  • Update the Google Chrome and Chromium-based browsers to the latest version IMMEDIATELY.
    (Remark: Users who applied the initial fix released on 12 March 2026 (Chrome 146.0.7680.75/76) or are running earlier versions should prioritize installing the latest update to ensure complete mitigation.)

 

Reference

 

 

Published on: 17 Mar 2026