Changeflow GovPing Data Privacy & Cybersecurity Google Chrome Vulnerability Advisory
Priority review Notice Added Final

Google Chrome Vulnerability Advisory

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 16th, 2026
Detected March 16th, 2026
Email

Summary

CERT-FR has issued an advisory regarding a vulnerability in Google Chrome, affecting versions prior to 146.0.7680.80. The vulnerability (CVE-2026-3909) is reportedly being actively exploited, and users are advised to update their software.

What changed

CERT-FR, the French national cybersecurity agency, has issued an advisory (CERTFR-2026-AVI-0297) detailing a vulnerability in Google Chrome, specifically affecting versions prior to 146.0.7680.80 on Windows, Mac, and Linux. The advisory highlights that CVE-2026-3909 is actively being exploited in the wild, posing a significant security risk.

Affected users and organizations are strongly advised to update their Google Chrome installations to the latest version (146.0.7680.80 or later) to mitigate the risk of exploitation. While the advisory itself does not impose direct regulatory obligations, failure to patch known, actively exploited vulnerabilities can lead to security breaches, data loss, and potential operational disruptions, which may have downstream compliance implications depending on an organization's specific security policies and regulatory environment.

What to do next

  1. Update Google Chrome to version 146.0.7680.80 or later.
  2. Review internal IT security policies for patching procedures related to actively exploited vulnerabilities.

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 16 mars 2026 N° CERTFR-2026-AVI-0297 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Vulnérabilité dans Google Chrome

Gestion du document

| Référence | CERTFR-2026-AVI-0297 |
| Titre | Vulnérabilité dans Google Chrome |
| Date de la première version | 16 mars 2026 |
| Date de la dernière version | 16 mars 2026 |
| Source(s) | Bulletin de sécurité Google Chrome du 13 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risque

  • Non spécifié par l'éditeur

Systèmes affectés

  • Chrome versions antérieures à 146.0.7680.80 pour Windows, Mac et Linux

Résumé

Une vulnérabilité a été découverte dans Google Chrome. Elle permet à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Google indique que la vulnérabilité CVE-2026-3909 est activement exploitée.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 16 mars 2026 Version initiale

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 16th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Manufacturers Technology companies
Geographic scope
National (France)

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Product Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.