
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3917 is a use-after-free vulnerability in the Agents component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.71 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher Syn4pse on February 11, 2026, and Google disclosed and patched it on March 10, 2026 with the Chrome 146 stable channel release. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Agents component. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to corrupt heap memory and redirect program execution. Exploitation requires a user to visit a specially crafted HTML page, making the attack vector network-based with required user interaction and no privileges needed. The Chromium bug tracker references issue 483569512, though full technical details remain restricted pending broad user patching (Chrome Release).
Successful exploitation can lead to heap corruption, which may enable a remote attacker to achieve arbitrary code execution in the context of the Chrome renderer process. This puts confidentiality, integrity, and availability of the affected system at high risk, potentially allowing an attacker to read sensitive browser data, execute malicious code, or crash the browser. If combined with a sandbox escape, the impact could extend to full system compromise (Chrome Release).
chrome.exe, chrome on Linux/Mac) spawning unexpected child processes or exhibiting abnormal memory usage patterns; crashes in Chrome's renderer process (check crash reports in chrome://crashes).Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which contain the fix for this vulnerability. Microsoft has also released a corresponding update for Edge (Chromium-based). Users and organizations should immediately update Google Chrome and Microsoft Edge to the latest available versions. As a temporary workaround where patching is not immediately feasible, restrict user access to untrusted or unknown websites and consider using network controls to limit browsing to approved domains (Chrome Release, Microsoft MSRC).
Security news outlets including GBHackers, SecurityOnline, CyberPress, and CyberNoz covered the Chrome 146 release, highlighting the 29 security fixes including CVE-2026-3917 alongside the Critical WebML flaw (CVE-2026-3913). Downstream Linux distributions including Debian, Fedora (42, 43, 44), and openSUSE issued Chromium security advisories incorporating the fix. The vulnerability received moderate community attention given the broader Chrome 146 update context, with no notable controversy or exceptional researcher commentary beyond standard patch reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."