PT-2026-25094 · Google+2 · Google Chrome+3

CVE-2026-3910

·

Published

2026-01-01

·

Updated

2026-07-17

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 146.0.7680.75 Microsoft Edge (affected versions not specified)
Description An inappropriate implementation in the V8 JavaScript engine, related to improper restriction of operations within the bounds of a memory buffer and incorrect code generation management, allows a remote attacker to execute arbitrary code inside a sandbox. This is achieved by enticing a user to visit a specially crafted HTML page. It has been reported that an exploit for this issue exists in the wild.
Recommendations Update Google Chrome to version 146.0.7680.75 or later.

Fix

RCE

DoS

Code Injection

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04246
CVE-2026-3910
OPENSUSE-SU-2026:10376-1
OPENSUSE-SU-2026:20372-1

Affected Products

Google Chrome
Edge
Red Os
V8