Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2358 articles · 161194 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-3910KEVEXPLOITEDPATCHED
google · chrome

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi

Description

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected Products

VendorProductVersions
googlechrome< 146.0.7680.75, 146.0.7680.178

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
applemacoscve_cpe95%
debiandebian linuxcert_advisory90%
fedorafedora linuxcert_advisory90%
googlechromecert_advisory90%
igeligel oscert_advisory90%

References

  • https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html(Vendor Advisory, Release Notes)
  • https://issues.chromium.org/issues/491410818(Permissions Required)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3910(US Government Resource)

Related News (6 articles)

Tier D
BleepingComputer4h ago
Google patches new Chrome zero-day flaw exploited in the wild
→ No new info (linked only)
Tier D
SecurityWeek5h ago
Google Patches 5th Chrome Zero-Day Exploited in 2026
→ No new info (linked only)
Tier D
CSO Online66d ago
Google patches fourth Chrome zero-day so far this year
→ No new info (linked only)
Tier D
SecurityWeek68d ago
Exploited Zero-Day Among 21 Vulnerabilities Patched in Chrome
→ No new info (linked only)
Tier D
BleepingComputer69d ago
Google fixes fourth Chrome zero-day exploited in attacks in 2026
→ No new info (linked only)
Tier B
BSI Advisories69d ago
[UPDATE] [hoch] Google Chrome/Microsoft Edge: Mehrere Schwachstellen
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
146.0.7680.75
CWECWE-94, CWE-119, CWE-20
PublishedMar 13, 2026
Last enriched66d agov2
Tags
zero-dayWebGPU
Trending Score115🔥
Source articles6
Independent4
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-5281EXPKEV
CVE-2026-5281: Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the render
Trending: 152
HIGHCVE-2026-3909EXPKEV
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Trending: 115
HIGHCVE-2025-48595EXP
CVE-2025-48595: In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to
Trending: 83
HIGHCVE-2026-11645EXP
CVE-2026-11645: Out of bounds read and write in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
Trending: 74
CRITICALCVE-2026-11680EXP
CVE-2026-11680: Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitra
Trending: 66

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Mar 13, 2026
Added to CISA KEV
Mar 13, 2026
Actively Exploited
Mar 13, 2026
Exploit Available
Mar 13, 2026
Patch Available
Mar 13, 2026
Discovered by ZDM
Apr 1, 2026
Updated: affectedVersions, cweIds, tags
Apr 3, 2026

Version History

v2
Last enriched 66d ago
v2Tier D66d ago

Updated affected versions and patch available to 146.0.7680.178, added new CWE and tags related to zero-day and WebGPU.

affectedVersionscweIdstags
via CSO Online
v168d ago

Initial creation