PT-2026-25093 · Google+2 · Google Chrome+3
CVE-2026-3909
·
Published
2026-01-01
·
Updated
2026-09-09
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 146.0.7680.75
Microsoft Edge (affected versions not specified)
Description
An out-of-bounds write exists in the Skia graphics library. This issue allows a remote attacker to perform out-of-bounds memory access by enticing a user to visit a specially crafted HTML page. This can impact the confidentiality, integrity, and availability of protected information. There are reports that this issue has been exploited in the wild.
Recommendations
Update Google Chrome to version 146.0.7680.75 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for Microsoft Edge.
Fix
RCE
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chromium
Google Chrome
Red Os
Skia