PT-2026-25093 · Google+2 · Skia+3
CVE-2026-3909
·
Publicado
2026-01-01
·
Atualizado
2026-06-14
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 146.0.7680.75
Chromium versions prior to 146.0.7680.75
Description
A high-severity out-of-bounds write flaw exists in the Skia graphics engine within Google Chrome and Chromium-based browsers. This vulnerability allows a remote attacker to perform out-of-bounds memory access through a crafted HTML page. The vulnerability is actively exploited in the wild, with reports indicating approximately 3.5 billion users are potentially at risk. The issue involves a memory corruption vulnerability that could lead to remote code execution. Exploitation occurs simply by visiting a malicious webpage. The vulnerability is identified as CVE-2026-3909 and has been added to CISA's Known Exploited Vulnerabilities catalog.
Recommendations
Update Google Chrome to version 146.0.7680.75 or later.
Update Chromium-based browsers to version 146.0.7680.75 or later.
Restart the browser after applying the update.
Apply enterprise browser patch policies.
Monitor endpoints for suspicious browser behavior.
Correção
RCE
DoS
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Chromium
Google Chrome
Red Os
Skia