PT-2026-25094 · Google+2 · Google Chrome+3
CVE-2026-3910
·
Published
2026-01-01
·
Updated
2026-07-17
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 146.0.7680.75
Microsoft Edge (affected versions not specified)
Description
An inappropriate implementation in the V8 JavaScript engine, related to improper restriction of operations within the bounds of a memory buffer and incorrect code generation management, allows a remote attacker to execute arbitrary code inside a sandbox. This is achieved by enticing a user to visit a specially crafted HTML page. It has been reported that an exploit for this issue exists in the wild.
Recommendations
Update Google Chrome to version 146.0.7680.75 or later.
Fix
RCE
DoS
Code Injection
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Chrome
Edge
Red Os
V8