
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3938 is an insufficient policy enforcement vulnerability in the Clipboard feature of Google Chrome that allows a remote attacker who has already compromised the renderer process to leak cross-origin data via a crafted HTML page. It affects all versions of Google Chrome prior to 146.0.7680.71 on Windows, Mac, and Linux. The vulnerability was reported by researcher "vicevirus" on January 10, 2026, and patched on March 10, 2026, as part of Chrome's stable channel update. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, Feedly).
The root cause is classified as CWE-284 (Improper Access Control) — specifically, insufficient enforcement of clipboard access policies within the Chrome renderer process. An attacker who has already achieved renderer process compromise can craft a malicious HTML page that abuses the relaxed clipboard policy to read or leak data from cross-origin contexts that should be inaccessible under the same-origin policy. Exploitation requires prior renderer compromise, meaning this vulnerability is typically chained with a more severe browser exploit rather than used in isolation. The Chromium bug tracker references issue 474763968, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation results in a confidentiality breach, allowing an attacker to leak sensitive cross-origin data accessible via the clipboard — such as content copied from other browser tabs or web applications. There is no integrity or availability impact; the vulnerability is limited to information disclosure. Because exploitation requires a pre-compromised renderer process, the practical blast radius is constrained, but in a chained attack scenario it could expose sensitive user data (e.g., passwords, tokens, or personal information) copied to the clipboard from other origins (Feedly).
Google has addressed this vulnerability in Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac), released on March 10, 2026. Users and organizations should update Google Chrome to version 146.0.7680.71 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Microsoft security update. No configuration-based workaround is available; patching is the only remediation. Organizations with high-risk users should additionally consider browser isolation technologies as a defense-in-depth measure (Chrome Releases, Microsoft MSRC).
GBHackers covered the broader Chrome 146 update, noting that the release addressed 29 security vulnerabilities across a range of severity levels. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-3938 has been observed, consistent with its Low severity rating and limited exploitation potential (GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."