CVE-2026-3920
vulnerability analysis and mitigation

Overview

CVE-2026-3920 is an out-of-bounds memory access vulnerability in the WebML component of Google Chrome, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. It affects all versions of Google Chrome prior to 146.0.7680.71 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported internally by Google on 2026-02-09 and publicly disclosed on 2026-03-10 with the Chrome 146 stable channel release. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).

Technical details

The vulnerability is classified under CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write), rooted in improper memory boundary enforcement within Chrome's WebML subsystem — the browser's machine learning inference engine. An attacker can craft a malicious HTML page that triggers out-of-bounds memory access when processed by the WebML component, potentially leading to heap corruption. Exploitation requires no special privileges but does require user interaction (visiting a malicious page). The Chromium issue tracker references bug ID 482875307 for this vulnerability (Chrome Releases).

Impact

Successful exploitation could allow a remote attacker to achieve arbitrary code execution with the privileges of the Chrome renderer process, impacting confidentiality, integrity, and availability at a high level. An attacker could read sensitive data from browser memory, modify application state, or crash the browser process. In a worst-case scenario, combined with a sandbox escape, this could lead to full system compromise (Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac), released on March 10, 2026. Users and organizations should update Google Chrome to version 146.0.7680.71 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Organizations should enforce automatic Chrome updates to ensure timely patching across all endpoints (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 146 update received coverage from security-focused outlets noting the breadth of the release — 29 security fixes in total, including multiple WebML-related vulnerabilities. Security news sites such as GBHackers and CyberPress highlighted the update, with some coverage specifically calling out the WebML flaws as notable given their concentration in a single component. The patch was also picked up by Linux distribution security advisories for Debian, Fedora, and openSUSE, reflecting broad downstream impact (GBHackers, CyberPress).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management