High severity8.8CISA KEVNVD Advisory· Published Mar 13, 2026· Updated Jun 17, 2026
CVE-2026-3910
CVE-2026-3910
Description
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Affected products
8- osv-coords4 versionspkg:apk/chainguard/chromiumpkg:apk/wolfi/chromiumpkg:rpm/opensuse/chromium&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/chromium&distro=openSUSE%20Tumbleweed
< 146.0.7680.75-r0+ 3 more
- (no CPE)range: < 146.0.7680.75-r0
- (no CPE)range: < 146.0.7680.75-r0
- (no CPE)range: < 146.0.7680.80-bp160.1.1
- (no CPE)range: < 146.0.7680.80-1.1
Patches
Vulnerability mechanics
References
3- chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.htmlnvdRelease NotesVendor Advisory
- issues.chromium.org/issues/491410818nvdPermissions Required
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
8- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News · Jun 15, 2026
- Google Chrome 0-Day Vulnerability Exploited in the Wild — Update NowCyber Security News · Jun 9, 2026
- Chrome's zero-day Whac-A-Mole continues with fifth exploited bug of the yearThe Register Security · Jun 9, 2026
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch NowThe Hacker News · Jun 9, 2026
- Google patches Chrome zero-day exploited in the wild (CVE-2026-11645)Help Net Security · Jun 9, 2026
- Google patches new Chrome zero-day flaw exploited in the wildBleepingComputer · Jun 9, 2026
- Google Patches 5th Chrome Zero-Day Exploited in 2026SecurityWeek · Jun 9, 2026
- 16th March – Threat Intelligence ReportCheck Point Research · Mar 16, 2026