Vulnerability record · CVE-2026-3910 · published 13 March 2026
CVE-2026-3910: Google Chrome V8 improper implementation allows sandbox code execution
Google · Chrome
Chrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer overflow. A crafted HTML page can trigger the flaw, letting a remote attacker run arbitrary code inside the browser sandbox. It matters because Chrome is widely deployed and the flaw is already listed in CISA KEV.
Description
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high integrity and confidentiality impact plus CISA KEV listing indicates active exploitation, though EPSS is low and no ransomware use is documented.
What it is
Chrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer overflow. A crafted HTML page can trigger the flaw, letting a remote attacker run arbitrary code inside the browser sandbox. It matters because Chrome is widely deployed and the flaw is already listed in CISA KEV.
Impact
An attacker who gets a victim to load a crafted page can execute arbitrary code within the Chrome sandbox, with high confidentiality, integrity and availability impact per the CVSS vector. Sandbox escape is not claimed in the record, so the gain is code execution inside the sandbox.
Attack surface
Reached over the network via a crafted HTML page rendered in Chrome; the CVSS vector shows no privileges required but user interaction required, so the victim must visit or open the page. No authentication is needed.
Exploitation
CISA added it to KEV on 2026-03-13 with a 2026-03-27 remediation due date, indicating known exploitation, while EPSS 30-day probability is 0.02 (79.7th percentile). The Chromium issue reference requires permissions, so technical detail is limited.
What to do
- Update Chrome to 146.0.7680.75 or later on all platforms and confirm the version in chrome://version.
- Apply vendor mitigations per CISA KEV guidance and BOD 22-01 for cloud services, or discontinue use if patching is not possible.
- Enforce automatic updates and restart browsers so the fixed build is actually running.
- Restrict or isolate browsing of untrusted web content where feasible until all endpoints are patched.
Detection
- Monitor for Chrome processes spawning unexpected child processes or writing unusual files, which can indicate V8 exploitation.
- Hunt for crashes or renderer terminations tied to Chrome versions below 146.0.7680.75.
- Track proxy and DNS logs for known malicious or newly registered domains delivering crafted HTML pages.
- Verify patch compliance across endpoints and flag hosts still running vulnerable Chrome builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-3910 to the Known Exploited Vulnerabilities catalog on 13 March 2026 as "Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 27 March 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html | Release NotesVendor Advisory |
| https://issues.chromium.org/issues/491410818 | Permissions Required |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3910 | US Government Resource |
Track CVE-2026-3910 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-3910), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.