CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability
Chromium: CVE-2026-3909 Out of bounds write in Skia
Other sources
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
— CISA
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2026-3909 exists in the wild.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Chrometo a version that resolves this vulnerability.Fixed in 146.0.7680.75 - Compensating control
Discontinue use of the product if mitigations are unavailable.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3909?
The severity of CVE-2026-3909 is classified as High.
How do I fix CVE-2026-3909?
To fix CVE-2026-3909, update Google Chrome to version 146.0.7680.75 or later.
What causes CVE-2026-3909?
CVE-2026-3909 is caused by an out of bounds write in Skia within Google Chrome.
Can CVE-2026-3909 be exploited remotely?
Yes, CVE-2026-3909 can be exploited remotely through crafted HTML pages.
Which versions of Google Chrome are affected by CVE-2026-3909?
Google Chrome versions prior to 146.0.7680.75 are affected by CVE-2026-3909.