CVE-2026-3909 is an out-of-bounds write vulnerability in Google Chrome's Skia component that requires user interaction (visiting a crafted HTML page). While actively exploited and severe for end-users, it does not affect internet-facing server applications and requires social engineering or phishing for exploitation.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: USER_INTERACTION
CVE Published: 2026-03-12
Added to CISA KEV: 2026-03-13 1 DAY BETWEEN CVE AND KEV
Attack Vector Network. Attack Complexity Low. Privileges Required None. Scope Unchanged."lessThan": "146.0.7680.75", "versionType": "custom"}]}], "references": [{"url": "https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html"}, {"url": "https://issues.chromium.org/issues/491421267"}], "descriptions": [{"lang": "en", "value": "Out of bounds write in Skia in Google Chrome prior to. 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their ...
Google addressed two high-severity vulnerabilities in the Chrome browser that have been exploited in attacks in the wild. Google has released security updates to address two high-severity vulnerabilities, tracked as CVE-2026-3909 and CVE-2026-3910, in the Chrome browser. The company is aware of attacks in the wild exploiting both flaws.