CVE detail
CVE-2026-3910
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.7 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
15 source links · newest first
Google has fixed 74 vulnerabilities in Chrome, including a high-severity zero-day (CVE-2026-11645) that has been exploited in the wild. “Google is aware that an exploit for CVE-2026-11645 exists in the wild,” the company said in a Monday security advisory. The fix has been shipped in Chrome 149.0.7827.102/.103 for Windows and macOS and Chrome 149.0.7827.102 for Linux, with the update rolling out to users over the coming days and weeks. About CVE-2026-11645 CVE-2026-11645 is an out-of-bounds … More →
newswww.helpnetsecurity.comJun 9, 2026, 11:24 AMGoogle fixed a new Chrome zero-day, tracked as CVE-2026-11645, in the V8 JavaScript engine, which is already being exploited in the wild. Google released emergency updates to address a new Chrome zero-day vulnerability, tracked as CVE-2026-11645, that has been exploited in the wild. This flaw is the fifth Chrome zero-day that is being exploited in […]
newssecurityaffairs.comJun 9, 2026, 10:38 AMThe vulnerability is tracked as CVE-2026-11645 and it was reported in late April by an anonymous researcher.
newswww.securityweek.comJun 9, 2026, 5:57 AMGoogle has patched another zero-day vulnerability in Chrome, its fourth this year. In patching the vulnerability, tracked as CVE-2026-5281, the company acknowledged that an exploit for it already exists in the wild. According to the report in NIST’s National Vulnerability Database, the vulnerability in Dawn, the implementation of WebGPU used by Chrome, allowed a remote […]
newswww.csoonline.comApr 3, 2026, 5:29 PM- Google fixes fourth actively exploited Chrome zero-day of 2026Security Affairs
Google fixed a new Chrome zero-day, tracked as CVE-2026-5281, in the WebGPU Dawn component that is already exploited in the wild. Google released Chrome updates fixing 21 vulnerabilities, including a new actively exploited zero-day tracked as CVE-2026-5281. The flaw is a use-after-free bug in Dawn, the WebGPU component used for graphics processing. Due to ongoing […]
newssecurityaffairs.comApr 1, 2026, 8:41 PM Google has announced fixes for CVE-2026-5281, a zero-day affecting Chrome’s Dawn component.
newswww.securityweek.comApr 1, 2026, 2:36 PMThe software refresh fixes eight memory safety bugs affecting seven Chrome components.
newswww.securityweek.comMar 24, 2026, 1:35 PM- 16th March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 16th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES United States-based medical technology company Stryker has suffered a cyberattack that caused a global disruption to its environment. The company said its surgical robotics, clinical communications platform, and life support monitors are […]
vendorresearch.checkpoint.comMar 16, 2026, 3:09 PM U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chrome flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added two Google Chrome flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: This week, Google released security updates to address two high-severity vulnerabilities, […]
newssecurityaffairs.comMar 13, 2026, 10:05 PMNo excerpt available.
Mitigationwww.cisa.govMar 13, 2026, 7:55 PM- https://issues.chromium.org/issues/491410818issues.chromium.org
No excerpt available.
Exploitissues.chromium.orgMar 13, 2026, 7:55 PM - https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.htmlchromereleases.googleblog.com
No excerpt available.
Vendor Advisorychromereleases.googleblog.comMar 13, 2026, 7:55 PM Threat actors are exploiting two high severity zero day vulnerabilities in the Chrome browser that experts say IT teams must patch immediately. Google has issued emergency patches for the two holes, CVE-2026-3909 and CVE-2026-3910. This comes just days after the release of 29 fixes for holes as part of March Patch Tuesday, and a zero day […]
newswww.csoonline.comMar 13, 2026, 7:54 PMGoogle addressed two high-severity vulnerabilities in the Chrome browser that have been exploited in attacks in the wild. Google has released security updates to address two high-severity vulnerabilities, tracked as CVE-2026-3909 and CVE-2026-3910, in the Chrome browser. The company is aware of attacks in the wild exploiting both flaws. “Google is aware that exploits for […]
newssecurityaffairs.comMar 13, 2026, 10:30 AMThe flaws can be exploited to manipulate data and bypass security restrictions, potentially leading to code execution.
newswww.securityweek.comMar 13, 2026, 7:47 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-10904CVSS 8.8 · High
Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium…
- CVE-2026-11688CVSS 8.8 · High
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromiu…
- CVE-2026-11157CVSS 5.4 · Medium
Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or…
- CVE-2026-10928CVSS 8.8 · High
Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-9976CVSS 8.8 · High
Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severi…
- CVE-2026-9938CVSS 8.8 · High
Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium…