
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3939 is an insufficient policy enforcement vulnerability in the PDF handling component of Google Chrome that allows a remote attacker to bypass navigation restrictions via a crafted PDF file. It was reported by researcher NDevTK on November 30, 2021, and publicly disclosed on March 10, 2026, as part of the Chrome 146 stable channel release. Affected versions include all Google Chrome releases prior to 146.0.7680.71, as well as Microsoft Edge (Chromium-based). Google rates this as Low severity (Chromium security severity), with a CVSS v3.1 base score of 5.3 (Medium) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-284 (Improper Access Control) and stems from insufficient policy enforcement within Chrome's PDF rendering subsystem (Chromium bug ID 40058077). When a user opens a specially crafted PDF file, Chrome fails to properly enforce its navigation restriction policies, allowing the embedded content to trigger unauthorized navigation to restricted resources or domains. No user interaction beyond opening the malicious PDF is required for exploitation, and no special privileges are needed on the attacker's side. The Chromium issue tracker entry remains restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation allows a remote attacker to bypass Chrome's navigation restriction policies, potentially redirecting users to restricted or malicious domains without their knowledge. The primary impact is on integrity (unauthorized navigation), with no direct confidentiality or availability impact per the CVSS assessment. In practice, this bypass could facilitate phishing attacks, malware distribution via drive-by downloads, or circumvention of enterprise content filtering policies enforced through browser navigation controls (Chrome Releases).
chrome.exe / chrome on Linux/Mac) initiating network connections to unexpected external hosts shortly after PDF file access.Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which addresses this vulnerability. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update via the Microsoft Security Response Center advisory. Organizations should prioritize updating all Chrome and Edge installations to the patched versions, enable automatic updates where possible, and advise users to exercise caution when opening PDF files from untrusted sources until patching is complete (Chrome Releases, Microsoft MSRC).
The Chrome 146 release was covered by security news outlets including GBHackers, which noted the update addresses 29 vulnerabilities in total. CVE-2026-3939 received limited individual attention given its Low severity rating. Downstream Linux distributions including Debian, openSUSE, and Fedora issued their own Chromium security advisories incorporating this fix. No notable researcher commentary or significant social media discussion specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."