
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3914 is an integer overflow vulnerability in the WebML component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by researcher "cinzinga" on February 4, 2026, and publicly disclosed on March 10, 2026, as part of the Chrome 146 stable channel release. All versions of Google Chrome prior to 146.0.7680.71 are affected, as is Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound), occurring within Chrome's WebML subsystem — the browser's implementation of the Web Machine Learning API. An integer overflow in this component can lead to heap memory corruption, as arithmetic on size or index values wraps around to unexpected values, causing subsequent memory operations to access or write out-of-bounds heap regions. Exploitation requires a user to visit a specially crafted HTML page that triggers the malformed WebML computation. The Chromium issue tracker entry (ID 481776048) is currently restricted pending broad user patching (Chrome Releases).
Successful exploitation could allow a remote attacker to corrupt heap memory within the Chrome renderer process, potentially leading to arbitrary code execution with the privileges of the user running Chrome. The vulnerability has high impact across confidentiality, integrity, and availability, meaning an attacker could read sensitive browser data, modify application state, or crash the browser. Because exploitation occurs within the renderer sandbox, a full compromise would likely require chaining with a sandbox escape, though heap corruption alone can enable significant data exposure or denial of service (Chrome Releases).
Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which contain the fix for this vulnerability. Users and organizations should update Google Chrome to version 146.0.7680.71 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Enabling automatic browser updates across enterprise environments is strongly recommended to ensure timely patching. No configuration-based workaround is available; updating is the only remediation (Chrome Releases, Microsoft MSRC).
The Chrome 146 update received broad coverage from security news outlets, with multiple publications highlighting the WebML vulnerabilities as notable given the high bug bounty rewards ($43,000 for CVE-2026-3914) and the concentration of flaws in the WebML component. Heise, GBHackers, CyberSecurityNews, and SecurityOnline all covered the release, noting the 29 total security fixes and the critical/high severity of the WebML-related CVEs. The Telefónica Tech cybersecurity briefing for the week of March 7–13, 2026 also flagged this update as a priority patching item (SecurityOnline, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."