Changeflow GovPing Vulnerability Management Google Chrome Skia Out-of-Bounds Write Vulnerab...
Priority review Notice Added Final

Google Chrome Skia Out-of-Bounds Write Vulnerability

Favicon for www.cisa.gov CISA Known Exploited Vulnerabilities (KEV)
Published March 12th, 2026
Detected March 14th, 2026
Email

Summary

CISA has added a known exploited vulnerability, CVE-2026-3909, affecting Google Chrome versions prior to 146.0.7680.75. This vulnerability allows remote attackers to perform out-of-bounds memory access via a crafted HTML page. Agencies are directed to apply mitigations by March 13, 2026.

What changed

CISA has identified and cataloged CVE-2026-3909, an "out of bounds write" vulnerability in Skia, a component of Google Chrome. This vulnerability, rated as High severity by Chromium, allows remote attackers to access out-of-bounds memory through specially crafted HTML pages. The affected versions are prior to Google Chrome 146.0.7680.75. This is a critical security update that requires immediate attention.

Federal agencies are required to apply available mitigations to prevent exploitation of this vulnerability by March 13, 2026, as per CISA's directive. Failure to comply with CISA directives can result in further action. Users and organizations should ensure their Google Chrome browsers are updated to version 146.0.7680.75 or later to address this security risk.

What to do next

  1. Update Google Chrome to version 146.0.7680.75 or later
  2. Apply available mitigations for CVE-2026-3909

Source document (simplified)

Required CVE Record Information

CNA: Chrome

Description

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Product Status

Learn more Versions 1 Total

Default Status: unknown

affected

  • affected from 146.0.7680.75 before 146.0.7680.75

References 2 Total

Authorized Data Publishers

Learn more

CISA-ADP

Updated:

2026-03-14

SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

SSVC 1 Total

Learn more
| Exploitation | Automatable | Technical Impact | Version | Date Accessed |
| --- | --- | --- | --- | --- |
| active | no | total | 2.0.3 | 2026-03-13 |

KEV 1 Total

Learn more
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3909 (2026-03-13)

CVSS 1 Total

Learn more
| Score | Severity | Version | Vector String |
| --- | --- | --- | --- |
| 8.8 | HIGH | 3.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
Various Federal Agencies
Published
March 12th, 2026
Compliance deadline
March 13th, 2026 (1 days ago)
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Consumers Technology companies
Geographic scope
National (US)

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Product Safety

Get Vulnerability Management alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CISA Known Exploited Vulnerabilities (KEV) publishes new changes.

Free. Unsubscribe anytime.