
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3926 is an out-of-bounds read vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to perform out-of-bounds memory access via a crafted HTML page. It was reported by researcher qymag1c on January 26, 2026, and publicly disclosed on March 10–11, 2026, as part of the Chrome 146 stable channel release. Affected versions include all Google Chrome releases prior to 146.0.7680.71, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal security classification (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's V8 JavaScript engine, which is responsible for parsing and executing JavaScript. An attacker can exploit this flaw by crafting a malicious HTML page that, when rendered by the browser, triggers V8 to read memory beyond the bounds of an allocated buffer. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but no authentication or special privileges are needed. The Chromium bug tracker references issue 478659010 for this vulnerability, though full technical details remain restricted pending broad user patching (Chrome Releases).
Successful exploitation could allow an attacker to read sensitive contents from the browser's memory, potentially exposing credentials, session tokens, or other confidential data processed by the V8 engine. The CVSS scoring reflects high impacts to confidentiality, integrity, and availability, suggesting that in certain scenarios the out-of-bounds read could be chained with other vulnerabilities to achieve code execution or browser compromise. All users running Chrome prior to 146.0.7680.71 on Windows, Mac, Linux, and ChromeOS, as well as Microsoft Edge (Chromium-based), are within the affected scope (Chrome Releases, Microsoft MSRC).
Google has addressed this vulnerability in Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac), released on March 10, 2026. Microsoft has also issued a corresponding update for Edge (Chromium-based). Users and administrators should update Chrome and Edge to the latest available versions immediately, and organizations should enforce automatic browser updates to ensure timely patching across all endpoints. No configuration-based workaround is available; updating to the patched version is the only remediation (Chrome Releases, Microsoft MSRC).
The Chrome 146 update, which included 29 security fixes, received coverage from security news outlets such as GBHackers, which highlighted the breadth of vulnerabilities addressed in the release. Downstream Linux distributions including Debian, Fedora (42, 43, 44), and openSUSE issued Chromium package updates to address this and related CVEs. Palo Alto Networks also published a Chromium monthly vulnerability update advisory (PAN-SA-2026-0004) referencing this CVE. Social media activity was limited, with some mentions on Mastodon via security-focused accounts (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."