CVE-2026-3914
vulnerability analysis and mitigation

Overview

CVE-2026-3914 is an integer overflow vulnerability in the WebML component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by researcher "cinzinga" on February 4, 2026, and publicly disclosed on March 10, 2026, as part of the Chrome 146 stable channel release. All versions of Google Chrome prior to 146.0.7680.71 are affected, as is Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound), occurring within Chrome's WebML subsystem — the browser's implementation of the Web Machine Learning API. An integer overflow in this component can lead to heap memory corruption, as arithmetic on size or index values wraps around to unexpected values, causing subsequent memory operations to access or write out-of-bounds heap regions. Exploitation requires a user to visit a specially crafted HTML page that triggers the malformed WebML computation. The Chromium issue tracker entry (ID 481776048) is currently restricted pending broad user patching (Chrome Releases).

Impact

Successful exploitation could allow a remote attacker to corrupt heap memory within the Chrome renderer process, potentially leading to arbitrary code execution with the privileges of the user running Chrome. The vulnerability has high impact across confidentiality, integrity, and availability, meaning an attacker could read sensitive browser data, modify application state, or crash the browser. Because exploitation occurs within the renderer sandbox, a full compromise would likely require chaining with a sandbox escape, though heap corruption alone can enable significant data exposure or denial of service (Chrome Releases).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 146.0.7680.71 or unpatched Chromium-based browsers (e.g., Microsoft Edge) using browser fingerprinting techniques on a malicious or compromised website.
  2. Craft malicious HTML page: Develop an HTML page that invokes the Web Machine Learning (WebML) API with inputs designed to trigger an integer overflow — for example, by supplying tensor dimensions or buffer sizes that cause arithmetic wraparound in the WebML implementation.
  3. Deliver the payload: Host the crafted page on an attacker-controlled server or inject it into a legitimate site via cross-site scripting. Lure the target user to visit the page through phishing, malvertising, or a watering hole attack.
  4. Trigger heap corruption: When the victim's browser processes the malicious WebML computation, the integer overflow causes heap memory to be corrupted, potentially overwriting adjacent heap metadata or object pointers.
  5. Achieve code execution (conditional): Leverage the heap corruption to gain control of program execution within the renderer process. A full exploit chain would require an additional sandbox escape vulnerability to break out of Chrome's renderer sandbox and execute code on the host system (Chrome Releases).

Mitigation and workarounds

Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which contain the fix for this vulnerability. Users and organizations should update Google Chrome to version 146.0.7680.71 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Enabling automatic browser updates across enterprise environments is strongly recommended to ensure timely patching. No configuration-based workaround is available; updating is the only remediation (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 146 update received broad coverage from security news outlets, with multiple publications highlighting the WebML vulnerabilities as notable given the high bug bounty rewards ($43,000 for CVE-2026-3914) and the concentration of flaws in the WebML component. Heise, GBHackers, CyberSecurityNews, and SecurityOnline all covered the release, noting the 29 total security fixes and the critical/high severity of the WebML-related CVEs. The Telefónica Tech cybersecurity briefing for the week of March 7–13, 2026 also flagged this update as a priority patching item (SecurityOnline, GBHackers).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management