
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3936 is a use-after-free vulnerability in the WebView component of Google Chrome on Android, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by researcher "Am4deu$" on February 5, 2026, and publicly disclosed on March 10–11, 2026, as part of the Chrome 146 stable channel release. The vulnerability affects Google Chrome versions prior to 146.0.7680.71 on Android, as well as Microsoft Edge (Chromium-based) builds prior to the equivalent patched version. It carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal security team (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's WebView component specifically on Android. A use-after-free condition arises when memory that has been freed is subsequently accessed, enabling an attacker to corrupt heap memory by causing the browser to process a specially crafted HTML page. Exploitation requires user interaction — specifically, a victim must visit a malicious web page — but no authentication or elevated privileges are needed on the attacker's side. The Chromium bug tracker references issue 481920229, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation could allow a remote attacker to corrupt heap memory in the Chrome WebView process on Android, potentially leading to arbitrary code execution within the context of the browser or a denial-of-service (application crash). Given the high CVSS scores for confidentiality, integrity, and availability, a fully weaponized exploit could result in sensitive data exposure, unauthorized actions on the device, or complete compromise of the browser sandbox. The attack surface is limited to Android devices running vulnerable Chrome versions, but the broad install base of Chrome on Android makes this a significant risk (Chrome Releases, Microsoft MSRC).
Google has addressed this vulnerability in Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac), released on March 10, 2026; Android users should update to the equivalent patched version via the Google Play Store. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory. No configuration-based workarounds have been published; updating to the patched version is the only recommended remediation. Enabling automatic updates for Chrome and Chrome-based browsers is strongly advised to ensure timely protection (Chrome Releases, Microsoft MSRC).
The Chrome 146 release, which included 29 security fixes, received coverage from security news outlets such as GBHackers, which highlighted the breadth of vulnerabilities addressed in the update. Social media activity was observed on Mastodon and Bluesky, with automated CVE tracking accounts noting the disclosure. Downstream Linux distributions including Debian, openSUSE, and Fedora issued their own Chromium security advisories referencing this CVE. Palo Alto Networks also published a Chromium monthly vulnerability update advisory (PAN-SA-2026-0004) that included CVE-2026-3936 (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."