HIGH KEV
chromium-browser: skia: chromium-browser: skia: Out of bounds write in Skia
Published Mar 12, 2026 ·Due Mar 27, 2026
8.8
HIGHCVSS 3.1
EPSS 2.30%
Description
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Affected products
-
- Version 146.0.7680.75StatusaffectedConstraints<146.0.7680.75
- Version
No data.
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Affected
Red Hat Enterprise Linux 7
webkitgtk4
Affected
Red Hat Enterprise Linux 8
webkit2gtk3
Affected
Red Hat Enterprise Linux 9
webkit2gtk3
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Affected | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk4 | Affected | n/a |
| Red Hat Enterprise Linux 8 | webkit2gtk3 | Affected | n/a |
| Red Hat Enterprise Linux 9 | webkit2gtk3 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Weaknesses (1)
References (10)
- https://access.redhat.com/security/cve/CVE-2026-3909 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2447195 Issue Tracking
- https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
- https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_13.html Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11734 Advisory
- https://issues.chromium.org/issues/491421267 Permissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2026-3909
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3909 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2026-3909
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-3909 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2447195 | Issue Tracking | |
| https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html | ||
| https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_13.html | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-11734 | Advisory | |
| https://issues.chromium.org/issues/491421267 | Permissions Required | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-3909 | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog | ||
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3909 | government-resourceUS Government Resource | |
| https://www.cve.org/CVERecord?id=CVE-2026-3909 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Mar 12, 2026
Updated Mar 24, 2026
Reserved Mar 11, 2026
Link CVE-2026-3909
CISA Vulnrichment
Updated Mar 13, 2026
ENISA EUVD
EUVD-2026-11734 Assigner Chrome
Published Mar 12, 2026
Updated Mar 24, 2026
Exploited since Mar 13, 2026
Link EUVD-2026-11734