Vulnerability record · CVE-2026-3909 · published 13 March 2026
CVE-2026-3909: Google Chrome Skia out-of-bounds write via crafted HTML page
Google · Chrome
Chrome's Skia graphics library contains an out-of-bounds write (CWE-787) that a remote attacker can trigger with a crafted HTML page. It is fixed in Chrome 146.0.7680.75, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-13, indicating exploitation in the wild. The flaw matters because it allows memory corruption in a component reachable from ordinary web content.
Description
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityConfirmed in-the-wild exploitation per CISA KEV with a near-term remediation deadline, though EPSS is low and the flaw requires user interaction.
What it is
Chrome's Skia graphics library contains an out-of-bounds write (CWE-787) that a remote attacker can trigger with a crafted HTML page. It is fixed in Chrome 146.0.7680.75, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-03-13, indicating exploitation in the wild. The flaw matters because it allows memory corruption in a component reachable from ordinary web content.
Impact
An attacker gains out-of-bounds memory access that can corrupt heap memory, with high impact to confidentiality, integrity and availability per the CVSS vector. In practice this can lead to code execution in the browser process or a crash, depending on how the corruption is shaped.
Attack surface
Reached over the network by rendering a crafted HTML page in Chrome; the CVSS vector shows no privileges required but user interaction required, meaning the victim must open or visit the malicious page. No authentication is needed.
Exploitation
Listed in CISA KEV with a 2026-03-27 remediation due date, so exploitation is confirmed in the wild. EPSS is low at 0.01629 (75th percentile), so mass scanning is not indicated, but targeted exploitation is.
What to do
- Update Chrome to 146.0.7680.75 or later on all platforms, and verify the version after restart.
- Track the CISA KEV due date of 2026-03-27 and confirm remediation across managed endpoints.
- If immediate patching is not possible, restrict browsing to trusted sites and consider disabling or sandboxing untrusted web content per vendor guidance.
- Apply BOD 22-01 guidance for cloud services that expose Chrome-based browsing or rendering.
- Monitor Chromium issue 491421267 and the Chrome stable channel release notes for follow-up fixes.
Detection
- Hunt for Chrome renderer crashes or abnormal terminations in endpoint telemetry around the patch window.
- Look for Chrome processes spawning unexpected child processes or making unusual network connections after visiting untrusted pages.
- Correlate proxy or DNS logs for known exploit-delivery domains with Chrome user agents below 146.0.7680.75.
- Alert on endpoints still reporting Chrome versions prior to 146.0.7680.75.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-3909 to the Known Exploited Vulnerabilities catalog on 13 March 2026 as "Google Skia Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_13.html | Release NotesVendor Advisory |
| https://issues.chromium.org/issues/491421267 | Permissions Required |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3909 | US Government Resource |
Track CVE-2026-3909 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-3909), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.