CVE-2026-3910
Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability
Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-03-27.
10 articles across 5 outlets · first covered Mar 13, 2026 · latest Sep 4, 2026
Coverage timeline
-
CISA Flags Actively Exploited Chrome Flaw as Sixth 2026 Zero-Daysecurityaffairs.com · Sep 4, 2026
-
Google Patches Actively Exploited Chrome V8 Zero Daysecurityaffairs.com · Sep 4, 2026
-
Google Patches Chrome Zero Day Exploited in V8 Attacksthehackernews.com · Sep 4, 2026
-
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & Morethehackernews.com · Mar 16, 2026
-
U.S. CISA adds Google Chrome flaws to its Known Exploited Vulnerabilities catalogsecurityaffairs.com · Mar 13, 2026
-
CISA Adds CVE-2026-3910 to Known Exploited Vulnerabilities Cataloguewww.cisa.gov · Mar 13, 2026
-
CISA Adds CVE-2026-3910 to Known Exploited Vulnerabilities Cataloguecisa.gov · Mar 13, 2026
-
Google fixed two new actively exploited flaws in the Chrome browsersecurityaffairs.com · Mar 13, 2026
-
Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8thehackernews.com · Mar 13, 2026
-
Chrome 146 Update Patches Two Exploited Zero-Dayswww.securityweek.com · Mar 13, 2026