Severity
High
Analysis Summary
CVE-2026-3909 CVSS:8.8
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
CVE-2026-3910 CVSS:8.8
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2026-3909
CVE-2026-3910
Affected Vendors
Affected Products
- Google Chrome 146.0.7680.75
Remediation
Upgrade to the latest version of Google Chrome, available from the Google Chrome Releases Website.