
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3932 is an insufficient policy enforcement vulnerability in the PDF component of Google Chrome on Android, allowing a remote attacker to bypass navigation restrictions via a crafted HTML page. It affects Google Chrome versions prior to 146.0.7680.71 on Android, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Ayato Shitomi on January 23, 2026, and patched on March 10, 2026, with the Chrome 146 stable channel release. It carries a CVSS v3.1 base score of 7.5 (High) and is rated Medium severity by the Chromium security team (Chrome Release, Microsoft MSRC).
The root cause is classified as CWE-284 (Improper Access Control), specifically insufficient policy enforcement within Chrome's PDF handling subsystem on Android. An attacker can craft a malicious HTML page that, when visited by a victim using Chrome on Android, exploits the PDF component's failure to properly enforce navigation restrictions, allowing redirection to unauthorized resources or bypassing security controls that govern where navigation from a PDF document is permitted. No user privileges are required, and the attack is delivered remotely over the network. The Chromium issue tracker references bug ID 478296121 for this vulnerability (Chrome Release).
Successful exploitation primarily affects integrity, as an attacker can bypass navigation restrictions enforced within Chrome's PDF viewer on Android, potentially redirecting users to unauthorized or malicious resources without their knowledge. Confidentiality and availability are not directly impacted according to the CVSS assessment. The scope is limited to the affected Android Chrome instance, but the bypass could be leveraged as part of a broader attack chain to expose users to phishing pages or malicious content (Chrome Release).
Update Google Chrome on Android to version 146.0.7680.71 or later, which was released on March 10, 2026, and contains the fix for this vulnerability. Microsoft Edge (Chromium-based) users should also apply the corresponding update referenced in the Microsoft Security Response Center advisory. No configuration-based workarounds have been published; updating to the patched version is the recommended and only confirmed remediation (Chrome Release, Microsoft MSRC).
The vulnerability was part of a broader Chrome 146 security update that addressed 29 security issues, including several Critical and High severity bugs, which drew general coverage from security news outlets. GBHackers reported on the Chrome update addressing 29 vulnerabilities, noting the range of severity levels included in the release. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2026-3932 has been identified, consistent with its Medium severity rating and lack of active exploitation (GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."