Chrome zero-days CVE-2026-3909, -3910 exploited
Google Chrome has two actively exploited zero-day vulnerabilities that could let attackers achieve arbitrary code execution.
CISecurity/MS-ISAC issued an advisory covering two vulnerabilities in Google Chrome, CVE-2026-3909 (an out-of-bounds write in Skia) and CVE-2026-3910 (an inappropriate implementation in V8), both of which Google has confirmed are being exploited in the wild. Successful exploitation could allow an attacker to execute arbitrary code in the context of the logged-in user, potentially leading to full system compromise depending on the user's privilege level.
The affected versions are Chrome prior to 146.0.7680.75/76 on Windows and macOS, and prior to 146.0.7680.75 on Linux. The advisory frames the likely attack vector as drive-by compromise, where a victim need only visit a malicious or compromised webpage to trigger exploitation. Given the presence of in-the-wild exploits for both flaws, organizations and home users should prioritize patching.
Recommended mitigations include immediate patching via vendor updates, enforcing least-privilege configurations, enabling anti-exploitation features (DEP, Exploit Guard, SIP/Gatekeeper), restricting web-based content via DNS/URL filtering, and general user security awareness training to reduce exposure to malicious links and drive-by download vectors.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-023
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free