
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3919 is a use-after-free vulnerability in the Extensions component of Google Chrome that allows an attacker who convinces a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. It affects all versions of Google Chrome prior to 146.0.7680.71, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Huinian Yang (@vmth6) of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd. on 2025-09-10, and was publicly disclosed on March 10–11, 2026 as part of the Chrome 146 stable channel release (Chrome Releases). It carries a CVSS v3.1 base score of 8.8 (High) (Feedly).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's Extensions subsystem. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to corrupt heap memory and achieve arbitrary code execution. Exploitation requires the victim to first install a malicious Chrome extension, after which a crafted HTML page can trigger the vulnerable code path. The bug was tracked internally as Chromium issue 444176961, and full technical details remain restricted pending broad user update (Chrome Releases).
Successful exploitation could result in high impact to confidentiality, integrity, and availability of the affected system, as reflected in the CVSS scoring. An attacker could leverage heap corruption to execute arbitrary code within the Chrome renderer or browser process, potentially enabling data theft, system compromise, or denial of service. The attack is network-based and requires only user interaction (installing a malicious extension), with no privileges required on the attacker's part (Feedly).
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ on Windows or ~/.config/google-chrome/Default/Extensions/ on Linux); suspicious extension manifest files or background scripts.cmd.exe, powershell.exe, bash, curl); Chrome renderer processes consuming abnormal memory or crashing repeatedly.Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which addresses this vulnerability; users should update immediately via Chrome's built-in update mechanism (Chrome Releases). Microsoft has also released a corresponding update for Edge (Chromium-based) (Microsoft MSRC). As a workaround, organizations should restrict extension installation to approved extensions only via enterprise policy, and users should avoid installing extensions from untrusted or unofficial sources. Security teams should audit installed extensions and remove any that are unknown or unverified.
The Chrome 146 release addressing this and 28 other vulnerabilities received coverage from several security news outlets, including GBHackers, CyberSecurityNews, CyberPress, and UnderCodeNews, which highlighted the breadth of the update and the inclusion of a Critical-rated WebML flaw alongside multiple High-severity use-after-free bugs (GBHackers, CyberSecurityNews). The vulnerability was also noted in the VulDB and infosec.exchange communities shortly after disclosure. No significant controversy or notable researcher commentary specific to CVE-2026-3919 has been identified beyond standard patch advisories.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."