
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3921 is a use-after-free vulnerability in the TextEncoding component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by Pranamya Keshkamat & Cantina.xyz on February 17, 2026, and publicly disclosed on March 10–11, 2026, as part of Chrome's stable channel update to version 146.0.7680.71. All versions of Google Chrome prior to 146.0.7680.71 are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's TextEncoding component — the subsystem responsible for handling character encoding and decoding operations within web pages. When a specially crafted HTML page triggers a specific sequence of operations in TextEncoding, a memory object can be freed and subsequently accessed again, resulting in heap corruption. Exploitation requires user interaction (e.g., visiting a malicious webpage), but no authentication or special privileges are needed on the attacker's side. The Chromium issue tracker reference is bug #484946544, though full technical details remain restricted pending broad user patching (Chrome Releases).
Successful exploitation can lead to arbitrary code execution within the Chrome browser process, with the privileges of the logged-in user. This could result in full compromise of browser security, unauthorized access to sensitive user data (cookies, saved credentials, browsing history), and potential lateral movement depending on the user's system privileges and browser permissions. Confidentiality, integrity, and availability are all rated as high impact (Chrome Releases).
cmd.exe, powershell.exe, bash, curl) or exhibiting abnormal memory usage patterns.Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which addresses this vulnerability. Users and organizations should immediately update all Chrome installations to version 146.0.7680.71 or later. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a supplementary measure, organizations should enforce browser update management policies, restrict users from visiting untrusted websites, and educate users about phishing risks. No configuration-based workaround is available; patching is the only definitive remediation (Chrome Releases, Microsoft MSRC).
The Chrome 146 update, which includes the fix for CVE-2026-3921 among 28 other security fixes, received coverage from multiple security news outlets including GBHackers, CyberSecurityNews, and CyberPress, which highlighted the breadth of the release (29 total fixes) and the presence of a Critical-rated WebML vulnerability alongside several High-severity use-after-free bugs. The update was also tracked by Tenable (Nessus) and Qualys scanners, and downstream Linux distributions including Debian, Fedora, and openSUSE issued their own Chromium security advisories. No notable controversy or unusual community sentiment was observed around this specific CVE (GBHackers, Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."