
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3931 is a heap buffer overflow vulnerability in the Skia graphics rendering engine within Google Chrome that allows a remote attacker to perform out-of-bounds memory access via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.71 and Microsoft Edge (Chromium-based). The vulnerability was reported by Huinian Yang (@vmth6) of Amber Security Lab, OPPO Mobile Telecommunications Corp. Ltd. on 2025-05-14, and was publicly disclosed on March 10–11, 2026, when Google released Chrome 146 to the stable channel. It carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal severity scale (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as a heap-based buffer overflow (CWE-122) and out-of-bounds write (CWE-787) in Skia, the open-source 2D graphics library used by Chrome for rendering. An attacker can exploit this by crafting a malicious HTML page that triggers improper memory access within Skia's rendering pipeline, causing the browser to write data beyond the bounds of an allocated heap buffer. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but no authentication or elevated privileges are needed. The Chromium bug tracker references issue 417599694, though details remain restricted pending broad user update (Chrome Releases).
Successful exploitation could result in memory corruption, potential information disclosure through reading sensitive heap memory, data integrity compromise, or denial of service (browser crash). In worst-case scenarios, depending on memory layout and exploitation complexity, arbitrary code execution within the Chrome renderer process may be achievable, which could then be leveraged for sandbox escape or further lateral movement on the host system. All three security pillars — confidentiality, integrity, and availability — are rated High impact in the CVSS scoring (Chrome Releases).
Google has addressed this vulnerability in Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac), released on March 10, 2026. Users and administrators should update Google Chrome to version 146.0.7680.71 or later immediately via the browser's built-in update mechanism or enterprise deployment tools. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory. As a general precaution, restrict user access to untrusted or unknown websites and enforce browser update policies across the organization (Chrome Releases, Microsoft MSRC).
The Chrome 146 stable release was covered by security-focused outlets including GBHackers, which noted the update addressed 29 vulnerabilities. Linux distribution maintainers for Debian, Fedora (42, 43, 44), openSUSE, and FreeBSD issued their own Chromium security advisories incorporating this fix. Community discussion on Mastodon and VulDB noted the vulnerability's medium Chromium severity rating. No exceptional researcher commentary or controversy was associated specifically with CVE-2026-3931 beyond standard patch reporting (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."