CISA added two Google Chrome vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after Google disclosed active exploitation in the wild. The flaws are CVE-2026-3909, an out-of-bounds write in Skia, and CVE-2026-3910, a Chromium V8 memory-safety issue that can allow arbitrary code execution inside the browser sandbox via a crafted HTML page. Google rated both issues as high severity with CVSS 8.8 and released fixes in Chrome 146.0.7680.75/76 for Windows and Mac and 146.0.7680.75 for Linux.
CISA's KEV entry states that CVE-2026-3910 may affect multiple Chromium-based browsers, including Google Chrome, Microsoft Edge, and Opera, while CVE-2026-3909 impacts the shared Skia component and may affect Chrome, ChromeOS, Android, Flutter, and other products depending on vendor implementation. Federal agencies were directed to apply vendor mitigations or discontinue use if fixes are unavailable, with a remediation due date of 2026-03-27. Neither source attributes the exploitation to a specific threat actor, but both confirm the vulnerabilities are being exploited and require prompt patching.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
In the same March 13, 2026 KEV update, CISA added CVE-2025-68613 in n8n, an SSRF flaw in Omnissa Workspace ONE UEM, and an unsafe deserialization issue in SolarWinds Web Help Desk. The entries directed agencies to apply vendor mitigations, follow cloud-service guidance, or discontinue use if mitigations were unavailable.
CISA added CVE-2026-3909 and CVE-2026-3910 to its Known Exploited Vulnerabilities catalog after Google confirmed active exploitation in the wild. The agency set a remediation deadline of March 27, 2026 for Federal Civilian Executive Branch agencies under BOD 22-01.
Microsoft released Edge version 126.0.2592.68 to address exposure related to the Chromium vulnerabilities CVE-2026-3909 and CVE-2026-3910. This extended remediation beyond Chrome to another Chromium-based browser.
Google released Chrome stable updates 146.0.7680.75/76 for Windows and Mac and 146.0.7680.75 for Linux to fix CVE-2026-3909 and CVE-2026-3910. The updates addressed two high-severity vulnerabilities that could be triggered via crafted web content.
Google reported CVE-2026-3909 and CVE-2026-3910 internally on March 10, 2026. The flaws affect Chrome's Skia graphics library and Chromium's V8 engine and were later confirmed as actively exploited in the wild.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
thecyberthrone.in
Open sourcesecurityaffairs.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.