CVE-2026-3916
vulnerability analysis and mitigation

Overview

CVE-2026-3916 is an out-of-bounds read vulnerability in the Web Speech component of Google Chrome that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It was reported by Grischa Hauser on 2026-02-09 and publicly disclosed on 2026-03-10 as part of the Chrome 146 stable channel release. The vulnerability affects all Google Chrome versions prior to 146.0.7680.71, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 9.6 (Critical) (Chrome Advisory, Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's Web Speech component. An attacker can exploit this flaw by crafting a malicious HTML page that triggers an out-of-bounds memory read in the Web Speech subsystem, which can then be leveraged to escape the Chrome sandbox. Exploitation requires user interaction — specifically, a victim must visit or be redirected to a malicious web page — but no authentication or special privileges are required on the attacker's side. The Chromium issue tracker references bug ID 482828615, though full technical details remain restricted pending broad user patching (Chrome Advisory).

Impact

Successful exploitation could allow a remote attacker to escape the Chrome browser sandbox and execute arbitrary code with the privileges of the underlying operating system user, potentially resulting in complete system compromise. This includes unauthorized access to sensitive data, system modification, and denial of service. Given the sandbox escape capability, the impact extends beyond the browser process itself, enabling potential lateral movement within the affected system (Chrome Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 146.0.7680.71 on Windows, Mac, or Linux using passive fingerprinting or social engineering.
  2. Craft malicious HTML page: Develop a web page that triggers the out-of-bounds read in Chrome's Web Speech component (e.g., by invoking the Web Speech API with specially crafted inputs that cause the browser to read beyond allocated memory boundaries).
  3. Deliver the payload: Host the malicious HTML page on an attacker-controlled server and lure the victim to visit it via phishing, malvertising, or a watering hole attack.
  4. Trigger the vulnerability: When the victim loads the page in a vulnerable Chrome version, the crafted content triggers the out-of-bounds read in the Web Speech subsystem.
  5. Achieve sandbox escape: Chain the memory disclosure from the out-of-bounds read with additional exploitation primitives to bypass Chrome's sandbox and execute arbitrary code at the OS level (Chrome Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser process to unknown external IPs following visits to unfamiliar or suspicious web pages; unusual DNS queries originating from the Chrome process.
  • Process: Unexpected child processes spawned by the Chrome renderer or GPU process (e.g., cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses.
  • Logs: Browser crash reports or unexpected termination of Chrome renderer processes; system event logs showing new process creation by the Chrome sandbox process.
  • File System: Unexpected files written to user-accessible directories by the Chrome process; new scheduled tasks, startup entries, or persistence mechanisms created shortly after browser activity.

Mitigation and workarounds

Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) to address this vulnerability; users should update immediately (Chrome Advisory). Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory (Microsoft MSRC). Patches are also available for downstream distributions including Debian, Fedora, and openSUSE. As a temporary workaround where immediate patching is not feasible, restrict user access to untrusted or unknown websites and ensure Chrome's automatic update mechanism is enabled. Enabling enterprise-managed update policies can help ensure fleet-wide patching.

Community reactions

The Chrome 146 release, which included 29 security fixes, received broad coverage from security media outlets including GBHackers, CyberSecurityNews, Heise, and SecurityOnline, with several articles highlighting the sandbox escape potential of CVE-2026-3916 alongside the critical WebML flaw (CVE-2026-3913) (GBHackers, Heise). The $36,000 bug bounty awarded to researcher Grischa Hauser was noted as indicative of the vulnerability's severity. No significant controversy or unusual community sentiment was observed beyond standard patch urgency advisories.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management