
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3916 is an out-of-bounds read vulnerability in the Web Speech component of Google Chrome that allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page. It was reported by Grischa Hauser on 2026-02-09 and publicly disclosed on 2026-03-10 as part of the Chrome 146 stable channel release. The vulnerability affects all Google Chrome versions prior to 146.0.7680.71, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 9.6 (Critical) (Chrome Advisory, Microsoft MSRC).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's Web Speech component. An attacker can exploit this flaw by crafting a malicious HTML page that triggers an out-of-bounds memory read in the Web Speech subsystem, which can then be leveraged to escape the Chrome sandbox. Exploitation requires user interaction — specifically, a victim must visit or be redirected to a malicious web page — but no authentication or special privileges are required on the attacker's side. The Chromium issue tracker references bug ID 482828615, though full technical details remain restricted pending broad user patching (Chrome Advisory).
Successful exploitation could allow a remote attacker to escape the Chrome browser sandbox and execute arbitrary code with the privileges of the underlying operating system user, potentially resulting in complete system compromise. This includes unauthorized access to sensitive data, system modification, and denial of service. Given the sandbox escape capability, the impact extends beyond the browser process itself, enabling potential lateral movement within the affected system (Chrome Advisory).
cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses.Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) to address this vulnerability; users should update immediately (Chrome Advisory). Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory (Microsoft MSRC). Patches are also available for downstream distributions including Debian, Fedora, and openSUSE. As a temporary workaround where immediate patching is not feasible, restrict user access to untrusted or unknown websites and ensure Chrome's automatic update mechanism is enabled. Enabling enterprise-managed update policies can help ensure fleet-wide patching.
The Chrome 146 release, which included 29 security fixes, received broad coverage from security media outlets including GBHackers, CyberSecurityNews, Heise, and SecurityOnline, with several articles highlighting the sandbox escape potential of CVE-2026-3916 alongside the critical WebML flaw (CVE-2026-3913) (GBHackers, Heise). The $36,000 bug bounty awarded to researcher Grischa Hauser was noted as indicative of the vulnerability's severity. No significant controversy or unusual community sentiment was observed beyond standard patch urgency advisories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."