Google Chrome Skia Out-of-Bounds Write Vulnerability
Summary
CISA has added a known exploited vulnerability, CVE-2026-3909, affecting Google Chrome versions prior to 146.0.7680.75. This vulnerability allows remote attackers to perform out-of-bounds memory access via a crafted HTML page. Agencies are directed to apply mitigations by March 13, 2026.
What changed
CISA has identified and cataloged CVE-2026-3909, an "out of bounds write" vulnerability in Skia, a component of Google Chrome. This vulnerability, rated as High severity by Chromium, allows remote attackers to access out-of-bounds memory through specially crafted HTML pages. The affected versions are prior to Google Chrome 146.0.7680.75. This is a critical security update that requires immediate attention.
Federal agencies are required to apply available mitigations to prevent exploitation of this vulnerability by March 13, 2026, as per CISA's directive. Failure to comply with CISA directives can result in further action. Users and organizations should ensure their Google Chrome browsers are updated to version 146.0.7680.75 or later to address this security risk.
What to do next
- Update Google Chrome to version 146.0.7680.75 or later
- Apply available mitigations for CVE-2026-3909
Source document (simplified)
Required CVE Record Information
CNA: Chrome
Description
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Product Status
Learn more Versions 1 Total
Default Status: unknown
affected
- affected from 146.0.7680.75 before 146.0.7680.75
References 2 Total
- https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
- https://issues.chromium.org/issues/491421267
Authorized Data Publishers
CISA-ADP
Updated:
2026-03-14
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.
SSVC 1 Total
Learn more
| Exploitation | Automatable | Technical Impact | Version | Date Accessed |
| --- | --- | --- | --- | --- |
| active | no | total | 2.0.3 | 2026-03-13 |
KEV 1 Total
Learn more
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3909 (2026-03-13)
CVSS 1 Total
Learn more
| Score | Severity | Version | Vector String |
| --- | --- | --- | --- |
| 8.8 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Vulnerability Management alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CISA Known Exploited Vulnerabilities (KEV) publishes new changes.