Intelligence BriefMarch 13, 2026
CVE-2026-3909

Google Chrome — Out-of-Bounds Write

CVSS 8.8 HIGHKEV CONFIRMED
EPSS Probability100.0%

CVE-2026-3909 (HIGH, CVSS 8.8) in Google actively exploited (CISA KEV): Out of bounds write in Skia in Google Chrome prior to 146.

Overview

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added 2026-03-13. Federal agencies must remediate by 2026-03-27.

Technical Details

CVSS Score: 8.8 (HIGH) CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H RiskScore: 98/100 (cvss weight: 26, exploit status weight: 26, epss weight: 7, age weight: 10, advisory weight: 5, epss percentile bonus: 24) EPSS Score: Not available Weaknesses (CWE): CWE-787, CWE-787

Why This Matters

A CVSS score of 8.8 (HIGH) places this vulnerability in the highest risk tier. With confirmed active exploitation in the wild (CISA KEV), this vulnerability represents an urgent patching priority for all affected organizations. Unpatched systems are exposed to remote attackers seeking to gain unauthorized access.

Affected Versions

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Apply all available patches from the vendor immediately. Prioritize internet-facing systems and critical infrastructure components. If patches are not available, implement network segmentation to limit exposure.

References


Powered by RiskScore — https://api.riskscore.dev