Exploitation observed; activity peaked at 45 mentions and remains active
Immediate actions
Patch apple chrome systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
⚡️0-Day Alert: Google Chrome RCE + EoP in the wild
• CVE-2026-3910: v8 Maglev JIT incorrect write barrier elimination for Smi representation in Phi edge cases => UaF or memory corruption
Impact: remote ACE in renderer via JavaScript code.
Same structural pattern invariant as seen in a recent WebKit jsc bug.
• CVE-2026-3909: Skia glyph cache key collision to out-of-bounds write in GPU process
Impact: at least a partial (full on some platforms) Sandbox Escape primitive.
Potentially reachable remotely via renderer media formats.
In the specific exploit it was likely pushed directly to IPC from a compromised renderer via CVE-2026-3910.
Both bugs patched since Chrome 146.0.7680.80 for Windows/Mac and 146.0.7680.80 for Linux
Post summary
The post reports two zero‑day CVEs (CVE‑2026‑3910 & CVE‑2026‑3909) that allow RCE and sandbox escape in Google Chrome, with confirmed active exploitation in the wild. Both vulnerabilities have been patched in Chrome 146.0.7680.80 across all platforms.
⚡️0-Day Alert: Google Chrome RCE + EoP in the wild • CVE-2026-3910: v8 Maglev JIT incorrect write barrier elimination for Smi representation in Phi edge cases => UaF or memory corruption Impact: remote ACE in renderer via JavaScript code. Same structural pattern invariant as seen in a recent WebKit jsc bug. • CVE-2026-3909: Skia glyph cache key collision to out-of-bounds write in GPU process Impact: at least a partial (full on some platforms) Sandbox Escape primitive. Potentially reachable remotely via renderer media formats. In the specific exploit it was likely pushed directly to IPC from a compromised renderer via CVE-2026-3910. Both bugs patched since Chrome 146.0.7680.80 for Windows/Mac and 146.0.7680.80 for Linux
Post summary
The text announces that CVE-2026-3910 and CVE-2026-3909 are actively exploited in the wild, provides technical details, and notes that they have already been patched.
(CVE-2026-3909)[491421267][Skia][Ganesh][Graphite]OOBW, exploited ITW
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
https://skia.googlesource.com/skia/+/0cab3e4ee34b3bca6ba7df676639d73ffe4b2135
Trigger:
https://skia.googlesource.com/skia/+/0cab3e4ee34b3bca6ba7df676639d73ffe4b2135/tests/AtlasOobTest.cpp
Reported by Google
Post summary
The text is a disclosure of CVE‑2026‑3909 with links to Google’s Chrome update, Skia repository, and a test file demonstrating the out‑of‑bounds write vulnerability, but it does not provide a functional exploit or patch details.
🛡️ We added Google Skia out-of-bounds write vulnerability CVE-2026-3909 & Google Chromium V8 unspecified vulnerability CVE-2026-3910 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity#InfoSec https://t.co/bjukrv3vvf
Post summary
The tweet announces the addition of two new CVEs to the KEV catalog, offering a link for more information but providing no exploit, patch, or active exploitation details.
Deux failles zero-day (CVE-2026-3909 et 3910) sont activement exploitées par des hackers. Alerte rouge pour les utilisateurs de Google Chrome, Microsoft Edge, Brave, Vivaldi et Opera https://l.frandroid.com/Tx4
Post summary
Two zero‑day browser vulnerabilities (CVE‑2026‑3909 and CVE‑2026‑3910) are reportedly being actively exploited by hackers, triggering a red alert for major browsers.
Google has released emergency updates to patch multiple actively exploited zero-day vulnerabilities in Chrome in early 2026, including CVE-2026-3909 (Skia out-of-bounds write) and CVE-2026-3910 (V8 inappropriate implementation). These critical flaws allow remote attackers to execute code via crafted websites, affecting desktop and mobile users. Update immediately to version 146.0.7680+.
BleepingComputer
BleepingComputer
+3
Recent & Active Chrome Exploits (2025-2026)
March 2026 (CVE-2026-3909/3910): Emergency patches for two zero-days, one in the Skia graphics library and another in the V8 JavaScript engine [3, BleepingComputer].
February 2026 (CVE-2026-2441): The first actively exploited zero-day of 2026 was patched in February, targeting Chrome, Android, and ChromeOS.
February 2026 (CSS Sandbox Escape): A critical vulnerability in the CSS engine was reported to allow sandbox escapes, requiring immediate extension auditing and browser updates [2, Instagram].
December 2025 (CVE-2025-14174): An out-of-bounds memory access vulnerability in ANGLE was exploited, prompting urgent CISA action [12, The Hacker News].
September-November 2025 (CVE-2025-10585): A type confusion vulnerability in the V8 engine was actively exploited in the wild [7, YouTube].
YouTube
YouTube
+4
Vulnerability Types and Impact
V8 Engine Vulnerabilities: The V8 JavaScript/WebAssembly engine is a frequent target for "type confusion" or "inappropriate implementation" bugs, allowing attackers to escape the browser sandbox.
Out-of-Bounds (OOB) Write/Memory Access: Flaws in components like Skia or ANGLE allow attackers to write data outside intended memory areas, resulting in crashes or code execution.
Remote Code Execution (RCE): Many of these exploits permit attackers to execute arbitrary code on the victim's machine, allowing them to steal data or install malware.
CIS Center for Internet Security
CIS Center for Internet Security
+4
How to Protect Yourself
Update Now: Go to chrome://settings/help to force an update to the latest version.
Restart Chrome: Patches are only applied after restarting the browser.
Check Extensions: Review installed extensions to ensure they are not malicious, as some attacks target browser security, per Instagram.
Automatic Updates: Keep automatic updates enabled for your OS and browser
Post summary
Google has released emergency Chrome patches for two actively exploited zero‑day CVEs (CVE‑2026‑3909 and CVE‑2026‑3910), enabling remote code execution via crafted websites; users are urged to update immediately.
CISA has listed CVE-2026-3909 and CVE-2026-3910 as known exploited vulnerabilities, confirmed to be active in the wild as zero‑day attacks, and Google has released patches for affected Chrome versions.
The post references CVE-2026-3909 and CVE-2026-3910, noting a zero‑day impact on desktop Chrome versions, but it provides none of the typical indicators such as PoC, exploit code, active exploitation evidence, or patch details.
Google releases an emergency Chrome update to patch two actively exploited zero-day vulnerabilities (CVE-2026-3909 & CVE-2026-3910). Update immediately.
#ChromeZeroDay#GoogleChrome#CVE#CyberSecurity#InfoSec#PatchAlert#BrowserSecurity#ZeroDay
https://securityonline.info/double-zero-day-threat-emergency-chrome-update-patches-actively-exploited-skia-and-v8-flaws/ https://t.co/RwRjaDvyBc
Post summary
Google released an emergency update for Chrome to patch two zero‑day vulnerabilities that were already being actively exploited.
Cette faille Chrome est réelle — deux zero-days (CVE-2026-3909 et CVE-2026-3910) activement exploités, corrigés le 16 mars dans Chrome 146.0.7680.75.
Mais c’est aussi le rappel parfait d’une habitude dangereuse : stocker ses mots de passe dans Chrome. Si la faille est exploitée avant la mise à jour, ils sont tous exposés.
J’explique pourquoi et comment s’en protéger → http://webologie.me/mots-de-passe-navigateur-danger/
Post summary
The post announces that two newly disclosed Chrome zero‑day CVEs (CVE-2026-3909 and CVE-2026-3910) were actively exploited and have been patched, warning users to update to prevent exposure of stored passwords.
🔥 Chrome 146 patches 2 zero-days under active exploit (CVE-2026-3909/3910)
Update ASAP—Google confirms in-the-wild attacks. Browser zero-days = fastest way to own users at scale.
Pair with web logs review for IOCs.
https://digitalforensicsmagazine.com/news-roundup-16th-march-2026/ #cybersecurity#zeroday
Post summary
The tweet announces that Chrome 146 patched two zero‑day CVEs (CVE‑2026‑3909/3910) which are actively exploited in the wild, urging users to update immediately.
تنبيه أمني عاجل لمستخدمي متصفح كروم (Chrome) 🚨
أصدرت شركة جوجل Google تحديثاً طارئاً لمليارات المستخدمين بعد اكتشاف ثغرات أمنية خطيرة من نوع "يوم الصفر" Zero-Day (وهي ثغرات يكتشفها المخترقون قبل الشركة).
الثغرات المعروفة باسم CVE-2026-3909 تتعرض حالياً لهجمات حقيقية من قبل قراصنة الإنترنت.
المستهدفون: جميع مستخدمي جوجل كروم Google Chrome على أجهزة الكمبيوتر (Windows, Mac, Linux).
الحل: التحديث فوراً لأحدث إصدار لتأمين بياناتك وحساباتك من الاختراق.
كيف تحمي نفسك؟
افتح المتصفح، اذهب إلى الإعدادات Settings ⬅️ حول كروم About Chrome، وسيقوم المتصفح بالتحديث تلقائياً.
Post summary
The advisory reports real-world attacks targeting CVE-2026-3909 in Chrome and urges users to update immediately.
🌐 CISA KEV: Two new Chrome vulnerabilities actively exploited (CVE-2026-3910, CVE-2026-3909)
Google Chrome V8 and Skia bugs allowing remote code execution via malicious web pages.
Every DIB contractor uses Chrome. Every Chrome instance is an attack surface.
Thread on what you need to know 👇
Post summary
The tweet announces that two Chrome CVEs are actively exploited, providing brief technical details of remote code execution but no PoC, exploit code, patches, or false‑positive claims.
⚡ Chrome zero-days CVE-2026-3909/3910 active—3.5B users at risk. Update to latest stable! https://www.youtube.com/watch?v=zQOn9YqhGuc
Post summary
The post alerts users to active exploitation of Chrome CVEs 2026-3909/3910, provides a YouTube link likely containing a PoC, and urges users to update to the latest stable release.
🚨 URGENT PATCH 🚨
Versi Indo dan lebih “awam friendly”
Dua bugs-nya Chrome, CVE-2026-3910 & CVE-2026-3909, lagi gencar dieksploitasi oleh attacker/hacker. CISA sudah memasukkan ini ke KEV catalog (Known Exploited Vulnerabilities) alias naik kelas dari CVE (Common Vulnerabilities and Exposures)
* CVE itu berpotensi membahayakan
* KEV itu diketahui sudah digunakan attacker
💀 Kenapa berbahaya?
Attacker bisa menjalankan kode di device korban cukup dengan membuat korban membuka page. Levelnya command di OS. Alias bisa buka file-file kita, curi foto dan video, hapus file, mencuri login password akun bank dan layanan finance lainnya, bahkan kalo mau attacker bisa download ransomeware atau backdoor dan dijalanin di device korban.
Semua itu, tanpa download, tanpa install, tanpa warning. Cukup buka halaman web yg disiapkan. 😐
⚠️ Bagaimana kita bisa kena?
Cuman 1x klik open page, biasanya dari malvertising (malicious advertising) atau link phishing. Cukup sesederhana itu.
Begitu klik dan page tujuan loading, kalau browser belum di-update, attacker bisa langsung masuk. Bisa juga paling cepat dia bikij otomasi ambil seluruh password yg tersimpan di device, serta session cookies. Korban nggak akan sadar, gw aja kagak mungkin sadar kalau gw nggak ngecek ketika itu berlangsung.
* Session cookies dicuri artinya attacker bisa login ke akun kamu, tanpa password.
🚨 Bugs dari software apa?
Browser berbasis Chromium: Chrome, Edge, Brave, Opera, Vivaldi, dll.
Mobile browser: Chrome dan Opera.
Juga berdampak ke: ChromeOS, Electron apps, Flutter (Skia), dan Debian (bookworm & trixie).
Safari nggak terdampak secara langsung dari kasus ini, tapi Apple juga baru keluarin patch celah lain di WebKit (CVE-2026-20643) yang juga bisa RCE (Remote Code Execution), risk level sama tingginya.
✅ Musti gimana?
Update browser.
Restart browser.
Selesai.
Selesai liburan, sebelum buka browser di PC kantor, jangan lupa update dulu.
Post summary
The post warns that CVE-2026-3910 and CVE-2026-3909 are actively exploited, describes RCE risks via malicious pages, and recommends updating browsers as a mitigation.
🌐 CISA KEV: Two new Chrome vulnerabilities actively exploited (CVE-2026-3910, CVE-2026-3909)
Google Chrome V8 and Skia bugs allowing remote code execution via malicious web pages.
Every DIS contractor uses Chrome. Every Chrome instance is an attack surface.
Thread on what you need to know 👇
Post summary
Two Chrome vulnerabilities (CVE-2026-3910 and CVE-2026-3909) are being actively exploited in the wild through malicious web pages, as confirmed by a CISA KEV announcement.
🚨 URGENT PATCH 🚨
Two Chrome 0-days (CVE-2026-3910 & CVE-2026-3909) are actively exploited in the wild. CISA already added them to the KEV catalog.
This is happening right now!
💀 Worst Case
Attacker can execute remote code on your machine just by making you open a malicious page. No download. No install. Just open the page.
⚠️ How it usually happens
Starts from malvertising or phishing link.
Once you open it, if your browser is not patched, attacker can silently grab your saved passwords and session cookies.
No warning. No popup. You won’t even notice.
🚨 Who is affected
Most Chromium-based browsers: Chrome, Edge, Brave, Opera, Vivaldi, and others.
Mobile: Chrome and Opera.
Also affected indirectly: ChromeOS, Electron apps, Flutter (Skia), and even Debian packages (bookworm & trixie).
Safari is not affected by this one, but Apple recently patched a separate WebKit RCE (CVE-2026-20643).
✅ FIX
Update your browser.
Restart it.
That’s it. Do it now.
Post summary
The post warns that CVE‑2026‑3910 and CVE‑2026‑3909 are being exploited in the wild, urging users to update affected browsers immediately.
#securityupdate#chrome
Google が,Chrome 146.0.7680.80 (Windows および Mac) および 146.0.7680.80 (Linux) をリリース.
CVE ベースで High 1 件の脆弱性に対処
「Google is aware that an exploit for CVE-2026-3909 exists in the wild.」
https://x.com/kawn2020/status/2033081168049090668
Post summary
Google released Chrome 146.0.7680.80 to patch CVE‑2026‑3909, noting that exploit code is already circulating in the wild.
📌 تحديث من Google لمعالجة ثغرات Chrome المستغلة بنشاط
أصدرت Google تحديثات أمنية حرجة لمتصفح Chrome لمعالجة ثغرتين (CVE-2026-3909 و CVE-2026-3910) يتم استغلالهما بنشاط في الهجمات. اكتشفت Google هذه الثغرات داخليًا في 10 مارس، مما يؤكد وجود حملات استغلال فعالة تستهدف مستخدمي المتصفح. تُشكل هذه الثغرات مخاطر عالية على أمن الأنظمة والبيانات بسبب الاستغلال الفعلي. يُنصح جميع المستخدمين بتحديث متصفح Chrome فورًا لضمان الحماية ضد هذه الهجمات النشطة.
🔗 للمزيد: https://www.security.nl/posting/928436/Google+komt+met+update+voor+actief+aangevallen+kwetsbaarheden+in+Chrome?channel=rss
Post summary
Google released critical updates for Chrome to fix CVE-2026-3909 and CVE-2026-3910, which are actively exploited. Users are urged to update immediately to protect against these threats.