CVE-2026-3922
vulnerability analysis and mitigation

Overview

CVE-2026-3922 is a use-after-free vulnerability in the MediaStream component of Google Chrome that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by researcher c6eed09fc8b174b0f3eebedcceb1e792 on February 18, 2026, and publicly disclosed on March 10–11, 2026, as part of the Chrome 146 stable channel release. All versions of Google Chrome prior to 146.0.7680.71 are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's MediaStream subsystem — the component responsible for handling real-time media capture and streaming APIs. A use-after-free condition arises when memory associated with a MediaStream object is freed but a dangling pointer to that memory is subsequently accessed, enabling heap corruption. Exploitation requires the victim to visit a specially crafted HTML page, meaning user interaction is a prerequisite, but no authentication or elevated privileges are needed on the attacker's side. The Chromium issue tracker entry is referenced as issue #485397139, though full bug details remain restricted pending broad user patching (Chrome Releases).

Impact

Successful exploitation could allow a remote attacker to achieve arbitrary code execution within the Chrome renderer process or cause the browser to crash, impacting availability. Given the heap corruption primitive, an attacker could potentially escape the browser sandbox with additional chaining, leading to full system compromise, data exfiltration, or installation of malware. Confidentiality, integrity, and availability are all rated as High impact under the CVSS scoring (Chrome Releases).

Mitigation and workarounds

Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which addresses this vulnerability. Users and administrators should immediately update Google Chrome to version 146.0.7680.71 or later; enabling automatic updates is strongly recommended to ensure timely patching. Microsoft Edge (Chromium-based) users should also apply the corresponding update referenced in the Microsoft Security Response Center advisory. Downstream distributions including Debian, Fedora, and openSUSE have also released updated Chromium packages (Chrome Releases, Microsoft MSRC).

Community reactions

Security news outlets including GBHackers and CyberPress covered the Chrome 146 update, noting it addressed 29 vulnerabilities including multiple use-after-free issues. The update was also highlighted in weekly threat landscape digests by Hawk-Eye.io. No notable individual researcher commentary specific to CVE-2026-3922 has been identified beyond the initial disclosure.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management