Google released Chrome 146 to the Stable channel for Windows, macOS, and Linux, addressing 29 security vulnerabilities in versions prior to 146.0.7680.71/72 (Windows/macOS) and 146.0.7680.71 (Linux). The most severe issue highlighted is CVE-2026-3913, a critical heap buffer overflow in WebML that could enable remote code execution when a user visits a maliciously crafted webpage; additional high-severity fixes include multiple memory-safety bugs such as use-after-free and out-of-bounds read conditions across browser components.
The Canadian Centre for Cyber Security issued advisory AV26-220 urging organizations to review Google’s guidance and apply the Chrome updates as they become available. A separate Canadian advisory, AV26-206, covers Microsoft Edge Stable updates for versions prior to 145.0.3800.97; while also Chromium-based, it is a distinct vendor release and should be tracked separately from the Chrome 146 patch cycle.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
On March 12, 2026, Google published another Chrome stable channel security advisory covering versions prior to 146.0.7680.75/76 on Windows and Mac and prior to 146.0.7680.75 on Linux. Google said exploits for CVE-2026-3909 and CVE-2026-3910 exist in the wild, indicating active exploitation.
On March 10, 2026, Google released Chrome 146 to the stable channel for Windows, macOS, and Linux, addressing 29 security vulnerabilities in versions prior to 146.0.7680.71/72 on Windows and Mac and prior to 146.0.7680.71 on Linux. The fixes included critical CVE-2026-3913, a heap buffer overflow in WebML that could enable remote code execution via a malicious web page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.