CVE-2026-3936
vulnerability analysis and mitigation

Overview

CVE-2026-3936 is a use-after-free vulnerability in the WebView component of Google Chrome on Android, allowing a remote attacker to potentially exploit heap corruption via a crafted HTML page. It was reported by researcher "Am4deu$" on February 5, 2026, and publicly disclosed on March 10–11, 2026, as part of the Chrome 146 stable channel release. The vulnerability affects Google Chrome versions prior to 146.0.7680.71 on Android, as well as Microsoft Edge (Chromium-based) builds prior to the equivalent patched version. It carries a CVSS v3.1 base score of 8.8 (High) and is rated Medium severity by Chromium's internal security team (Chrome Releases, Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's WebView component specifically on Android. A use-after-free condition arises when memory that has been freed is subsequently accessed, enabling an attacker to corrupt heap memory by causing the browser to process a specially crafted HTML page. Exploitation requires user interaction — specifically, a victim must visit a malicious web page — but no authentication or elevated privileges are needed on the attacker's side. The Chromium bug tracker references issue 481920229, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases).

Impact

Successful exploitation could allow a remote attacker to corrupt heap memory in the Chrome WebView process on Android, potentially leading to arbitrary code execution within the context of the browser or a denial-of-service (application crash). Given the high CVSS scores for confidentiality, integrity, and availability, a fully weaponized exploit could result in sensitive data exposure, unauthorized actions on the device, or complete compromise of the browser sandbox. The attack surface is limited to Android devices running vulnerable Chrome versions, but the broad install base of Chrome on Android makes this a significant risk (Chrome Releases, Microsoft MSRC).

Exploitation steps

  1. Reconnaissance: Identify Android users running Google Chrome versions prior to 146.0.7680.71, potentially via social engineering or targeting users of apps that embed Chrome WebView.
  2. Craft malicious HTML page: Develop a specially crafted HTML page that triggers the use-after-free condition in Chrome's WebView component, manipulating object lifecycle to cause a freed memory region to be accessed.
  3. Deliver the payload: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing, malicious ads, or a compromised website — user interaction (page visit) is required.
  4. Trigger heap corruption: When the victim's Android Chrome WebView processes the crafted HTML, the use-after-free is triggered, corrupting heap memory in the browser process.
  5. Achieve code execution or crash: Depending on exploit reliability and heap layout, the attacker may achieve arbitrary code execution within the Chrome renderer process or cause a denial-of-service crash (Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac), released on March 10, 2026; Android users should update to the equivalent patched version via the Google Play Store. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory. No configuration-based workarounds have been published; updating to the patched version is the only recommended remediation. Enabling automatic updates for Chrome and Chrome-based browsers is strongly advised to ensure timely protection (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 146 release, which included 29 security fixes, received coverage from security news outlets such as GBHackers, which highlighted the breadth of vulnerabilities addressed in the update. Social media activity was observed on Mastodon and Bluesky, with automated CVE tracking accounts noting the disclosure. Downstream Linux distributions including Debian, openSUSE, and Fedora issued their own Chromium security advisories referencing this CVE. Palo Alto Networks also published a Chromium monthly vulnerability update advisory (PAN-SA-2026-0004) that included CVE-2026-3936 (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management