
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3922 is a use-after-free vulnerability in the MediaStream component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on February 18, 2026, and publicly disclosed on March 10–11, 2026, as part of the Chrome 146 stable channel release. All versions of Google Chrome prior to 146.0.7680.71 are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's MediaStream subsystem — the component responsible for handling real-time media capture and streaming APIs. A use-after-free condition arises when memory associated with a MediaStream object is freed but a dangling pointer to that memory is subsequently accessed, enabling heap corruption. Exploitation requires the victim to visit a specially crafted HTML page, meaning user interaction is a prerequisite, but no authentication or elevated privileges are needed on the attacker's side. The Chromium issue tracker entry is referenced as issue #485397139, though full bug details remain restricted pending broad user patching (Chrome Releases).
Successful exploitation could allow a remote attacker to achieve arbitrary code execution within the Chrome renderer process or cause the browser to crash, impacting availability. Given the heap corruption primitive, an attacker could potentially escape the browser sandbox with additional chaining, leading to full system compromise, data exfiltration, or installation of malware. Confidentiality, integrity, and availability are all rated as High impact under the CVSS scoring (Chrome Releases).
Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which addresses this vulnerability. Users and administrators should immediately update Google Chrome to version 146.0.7680.71 or later; enabling automatic updates is strongly recommended to ensure timely patching. Microsoft Edge (Chromium-based) users should also apply the corresponding update referenced in the Microsoft Security Response Center advisory. Downstream distributions including Debian, Fedora, and openSUSE have also released updated Chromium packages (Chrome Releases, Microsoft MSRC).
Security news outlets including GBHackers and CyberPress covered the Chrome 146 update, noting it addressed 29 vulnerabilities including multiple use-after-free issues. The update was also highlighted in weekly threat landscape digests by Hawk-Eye.io. No notable individual researcher commentary specific to CVE-2026-3922 has been identified beyond the initial disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."