PT-2026-25093 · Chromium+1 · Chromium+2

Published

2026-01-01

·

Updated

2026-04-01

·

CVE-2026-3909

CVSS v2.0

10

High

AV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 146.0.7680.75 Chromium versions prior to 146.0.7680.75
Description A high-severity out-of-bounds write flaw exists in the Skia graphics engine within Google Chrome and Chromium-based browsers. This vulnerability allows a remote attacker to perform out-of-bounds memory access through a crafted HTML page. The vulnerability is actively exploited in the wild, with reports indicating approximately 3.5 billion users are potentially at risk. The issue involves a memory corruption vulnerability that could lead to remote code execution. Exploitation occurs simply by visiting a malicious webpage. The vulnerability is identified as CVE-2026-3909 and has been added to CISA's Known Exploited Vulnerabilities catalog.
Recommendations Update Google Chrome to version 146.0.7680.75 or later. Update Chromium-based browsers to version 146.0.7680.75 or later. Restart the browser after applying the update. Apply enterprise browser patch policies. Monitor endpoints for suspicious browser behavior.

Fix

RCE

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-04245
CVE-2026-3909
OPENSUSE-SU-2026:10376-1
OPENSUSE-SU-2026:20372-1

Affected Products

Chromium
Google Chrome
Skia