PT-2026-25093 · Google+2 · Google Chrome+3

CVE-2026-3909

·

Published

2026-01-01

·

Updated

2026-09-09

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 146.0.7680.75 Microsoft Edge (affected versions not specified)
Description An out-of-bounds write exists in the Skia graphics library. This issue allows a remote attacker to perform out-of-bounds memory access by enticing a user to visit a specially crafted HTML page. This can impact the confidentiality, integrity, and availability of protected information. There are reports that this issue has been exploited in the wild.
Recommendations Update Google Chrome to version 146.0.7680.75 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability for Microsoft Edge.

Fix

RCE

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04245
CVE-2026-3909
OPENSUSE-SU-2026:10376-1
OPENSUSE-SU-2026:20372-1
OPENSUSE-SU-2026:20460-1

Affected Products

Chromium
Google Chrome
Red Os
Skia