Exploitation observed; activity peaked at 42 mentions and remains active
Immediate actions
Patch apple chrome systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Active Exploitation15Disclosure2False Positive1General1Patch6
2026-03-15
18
Active Exploitation12Disclosure2General2Patch2
2026-03-16
17
Active Exploitation7General3Patch7
2026-03-17
8
Active Exploitation5Disclosure1Patch2
2026-03-18
1
Active Exploitation1
2026-03-19
2
Active Exploitation2
2026-03-20
3
Active Exploitation2Patch1
2026-03-21
5
Active Exploitation2Patch3
2026-03-22
4
Active Exploitation1Patch3
2026-03-23
2
Active Exploitation1Patch1
2026-03-24
1
Active Exploitation1
2026-03-26
4
Active Exploitation2General2
2026-03-27
1
Patch1
2026-04-01
1
Patch1
2026-04-06
1
General1
2026-04-15
1
Active Exploitation1
2026-04-17
2
Active Exploitation2
2026-05-02
1
General1
2026-05-03
1
General1
2026-05-15
2
Active Exploitation1Disclosure1
2026-06-06
1
Disclosure1
2026-06-09
1
Active Exploitation1
2026-06-12
2
General1PoC1
2026-06-26
1
Patch1
2026-07-08
2
General1PoC1
2026-07-17
1
Patch1
2026-09-06
1
Active Exploitation1
2026-09-09
2
Active Exploitation2
>Full discourse20 posts
RewriteLab@RewriteLab·
PoC
We published a new research article on the Chromium 146 Renderer Process!
In this article, we start from the CVE-2026-3910 Maglev write barrier elision bug and walk through the full exploit chain: building a V8 heap R/W primitive via a GC-induced UAF, achieving an out-of-sandbox read using WebAssembly internals, abusing JSPI UAF and StackMemory / JumpBuffer, and ultimately reaching renderer process RCE.
Our goal was to provide a structured explanation of how modern V8 exploitation works in practice, from compiler-level bug analysis to sandbox-boundary primitives and final code execution. Huge thanks to our team member @m411k_ for conducting this research!
Check out the PoC!
Full article:
https://research.rewritelab.org/2026/06/11/%5BENG%5D%20Pwning%20Chromium%20146%20Renderer%20Process/
Post summary
Researchers present the complete exploit chain for CVE‑2026‑3910, including a PoC leading to renderer‑process RCE, without evidence of real‑world exploitation or a fix.
⚡️0-Day Alert: Google Chrome RCE + EoP in the wild
• CVE-2026-3910: v8 Maglev JIT incorrect write barrier elimination for Smi representation in Phi edge cases => UaF or memory corruption
Impact: remote ACE in renderer via JavaScript code.
Same structural pattern invariant as seen in a recent WebKit jsc bug.
• CVE-2026-3909: Skia glyph cache key collision to out-of-bounds write in GPU process
Impact: at least a partial (full on some platforms) Sandbox Escape primitive.
Potentially reachable remotely via renderer media formats.
In the specific exploit it was likely pushed directly to IPC from a compromised renderer via CVE-2026-3910.
Both bugs patched since Chrome 146.0.7680.80 for Windows/Mac and 146.0.7680.80 for Linux
Post summary
The post reports active exploitation of two Chrome CVEs, outlines the technical details and impact, and confirms patches are available.
⚡️0-Day Alert: Google Chrome RCE + EoP in the wild • CVE-2026-3910: v8 Maglev JIT incorrect write barrier elimination for Smi representation in Phi edge cases => UaF or memory corruption Impact: remote ACE in renderer via JavaScript code. Same structural pattern invariant as seen in a recent WebKit jsc bug. • CVE-2026-3909: Skia glyph cache key collision to out-of-bounds write in GPU process Impact: at least a partial (full on some platforms) Sandbox Escape primitive. Potentially reachable remotely via renderer media formats. In the specific exploit it was likely pushed directly to IPC from a compromised renderer via CVE-2026-3910. Both bugs patched since Chrome 146.0.7680.80 for Windows/Mac and 146.0.7680.80 for Linux
Post summary
The text confirms that CVE-2026-3910 and CVE-2026-3909 have been actively exploited in the wild, delivering remote code execution and sandbox escape in Google Chrome; patches have been released in Chrome 146.0.7680.80.
🛡️ We added Google Skia out-of-bounds write vulnerability CVE-2026-3909 & Google Chromium V8 unspecified vulnerability CVE-2026-3910 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity#InfoSec https://t.co/bjukrv3vvf
Post summary
The tweet announces that CVE‑2026‑3909 and CVE‑2026‑3910 are now in DHS’s KEV Catalog, indicating active exploitation, but no PoC, exploit code, or patch information is included.
(CVE-2026-3910)[491410818][maglev]Inappropriate implementation(Phi untagging issues), exploited ITW
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
https://chromium-review.googlesource.com/c/v8/v8/+/7653638
Reported by Google
Post summary
CVE-2026-3910, a phi-untagging implementation flaw, has been actively exploited in the wild and has already been addressed in Google's Chrome release notes.
Google has released emergency updates to patch multiple actively exploited zero-day vulnerabilities in Chrome in early 2026, including CVE-2026-3909 (Skia out-of-bounds write) and CVE-2026-3910 (V8 inappropriate implementation). These critical flaws allow remote attackers to execute code via crafted websites, affecting desktop and mobile users. Update immediately to version 146.0.7680+.
BleepingComputer
BleepingComputer
+3
Recent & Active Chrome Exploits (2025-2026)
March 2026 (CVE-2026-3909/3910): Emergency patches for two zero-days, one in the Skia graphics library and another in the V8 JavaScript engine [3, BleepingComputer].
February 2026 (CVE-2026-2441): The first actively exploited zero-day of 2026 was patched in February, targeting Chrome, Android, and ChromeOS.
February 2026 (CSS Sandbox Escape): A critical vulnerability in the CSS engine was reported to allow sandbox escapes, requiring immediate extension auditing and browser updates [2, Instagram].
December 2025 (CVE-2025-14174): An out-of-bounds memory access vulnerability in ANGLE was exploited, prompting urgent CISA action [12, The Hacker News].
September-November 2025 (CVE-2025-10585): A type confusion vulnerability in the V8 engine was actively exploited in the wild [7, YouTube].
YouTube
YouTube
+4
Vulnerability Types and Impact
V8 Engine Vulnerabilities: The V8 JavaScript/WebAssembly engine is a frequent target for "type confusion" or "inappropriate implementation" bugs, allowing attackers to escape the browser sandbox.
Out-of-Bounds (OOB) Write/Memory Access: Flaws in components like Skia or ANGLE allow attackers to write data outside intended memory areas, resulting in crashes or code execution.
Remote Code Execution (RCE): Many of these exploits permit attackers to execute arbitrary code on the victim's machine, allowing them to steal data or install malware.
CIS Center for Internet Security
CIS Center for Internet Security
+4
How to Protect Yourself
Update Now: Go to chrome://settings/help to force an update to the latest version.
Restart Chrome: Patches are only applied after restarting the browser.
Check Extensions: Review installed extensions to ensure they are not malicious, as some attacks target browser security, per Instagram.
Automatic Updates: Keep automatic updates enabled for your OS and browser
Post summary
Google issued emergency patches for two actively exploited zero‑day Chrome vulnerabilities, urging immediate updates to prevent remote code execution.
More to the point.
CVE-2025-9132 - OOB write
CVE-2025-12036 - inappropriate implementation
CVE-2025-13224 - type confusion (CVSS 8.8)
CVE-2025-10585 - type confusion
CVE-2025-13223 - type confusion (CVSS 8.8)
CVE-2026-3910 - (CVSS 8.8, CISA KEV)
Fuck v8.
Post summary
The brief note lists several 2025–2026 CVEs with their types, CVSS scores, and identifies CVE‑2026‑3910 as a CISA Key Exploit Vulnerability, indicating it's a disclosed vulnerability likely being exploited.
Make sure you're on the latest version of Chrome or any Chromium based browser! Please share this everywhere! 🤗 You can get more information on the vulnerability @ https://app.opencve.io/cve/CVE-2026-3910
Post summary
The message urges users to update to the latest Chrome versions for CVE‑2026‑3910, referencing the CVE page but providing no technical details, PoC, or exploit information.
CISA confirms that CVE‑2026‑3909 and CVE‑2026‑3910 are actively exploited in the wild as zero‑day attacks, with detailed vulnerability data provided but no public PoC or fix detailed.
Android System WebView June 2026 update fixes 4 serious vulnerabilities. Here's what they were.
Android System WebView (MWebView 2026.06.13): Besides CVE-2026-3910, addresses three other high-severity issues: an integer overflow in WebGL, a use-after-free in the speech synthesis API, and a DOM cross-origin bypass affecting offline service workers.
The 4 WebView vulnerabilities fixed explained in plain English:
🔴 CVE-2026-3910 (Critical):
▪ Any website could potentially execute code on your phone
▪ The type of vulnerability state-sponsored hackers exploit for targeted attacks
🟠 INTEGER OVERFLOW IN WEBGL:
▪ Viewing specially crafted 3D web content → potential code execution
▪ Affects: any app using WebGL (Instagram, games with web views)
🟠 USE-AFTER-FREE IN SPEECH SYNTHESIS:
▪ Using text-to-speech in a browser → memory corruption possible
▪ Could allow attacker to read private memory regions
🟠 DOM CROSS-ORIGIN BYPASS:
▪ A website could read content from another website in offline service workers
▪ Your cached offline banking app → potentially readable by a malicious site
HOW TO UPDATE ANDROID SYSTEM WEBVIEW:
Google Play Store → search "Android System WebView" → Update
This is NOT automatic on all devices.
You must manually update it from the Play Store.
Every app that renders web content on your Galaxy uses WebView.
That's: Instagram · WhatsApp web preview · banking apps · news apps.
Update it. Now. 🔐
#AndroidWebView#Samsung#Security#CVE#Android
Post summary
Google released an Android System WebView 2026.06.13 update that fixes four high‑severity vulnerabilities, including CVE-2026-3910, and urges users to manually update the app via the Play Store.
The post links to CVE-2026-3909 and CVE-2026-3910, noting they target Chrome on desktop platforms, but provides no PoC, exploit code, patches, or evidence of active exploitation, making it a general reference.
Google releases an emergency Chrome update to patch two actively exploited zero-day vulnerabilities (CVE-2026-3909 & CVE-2026-3910). Update immediately.
#ChromeZeroDay#GoogleChrome#CVE#CyberSecurity#InfoSec#PatchAlert#BrowserSecurity#ZeroDay
https://securityonline.info/double-zero-day-threat-emergency-chrome-update-patches-actively-exploited-skia-and-v8-flaws/ https://t.co/RwRjaDvyBc
Post summary
Google issued an emergency Chrome update to fix CVE‑2026‑3909 and CVE‑2026‑3910, which are actively exploited zero‑day vulnerabilities.
Cette faille Chrome est réelle — deux zero-days (CVE-2026-3909 et CVE-2026-3910) activement exploités, corrigés le 16 mars dans Chrome 146.0.7680.75.
Mais c’est aussi le rappel parfait d’une habitude dangereuse : stocker ses mots de passe dans Chrome. Si la faille est exploitée avant la mise à jour, ils sont tous exposés.
J’explique pourquoi et comment s’en protéger → http://webologie.me/mots-de-passe-navigateur-danger/
Post summary
Two Chrome zero‑day CVEs (CVE‑2026‑3909, CVE‑2026‑3910) were reported as actively exploited and patched on March 16, with advice to avoid storing passwords in the browser.
🌐 CISA KEV: Two new Chrome vulnerabilities actively exploited (CVE-2026-3910, CVE-2026-3909)
Google Chrome V8 and Skia bugs allowing remote code execution via malicious web pages.
Every DIB contractor uses Chrome. Every Chrome instance is an attack surface.
Thread on what you need to know 👇
Post summary
CISA KEV reports that CVE-2026-3910 and CVE-2026-3909 are actively exploited in Chrome, with bugs in V8 and Skia enabling remote code execution through malicious web pages.
🚨 URGENT PATCH 🚨
Versi Indo dan lebih “awam friendly”
Dua bugs-nya Chrome, CVE-2026-3910 & CVE-2026-3909, lagi gencar dieksploitasi oleh attacker/hacker. CISA sudah memasukkan ini ke KEV catalog (Known Exploited Vulnerabilities) alias naik kelas dari CVE (Common Vulnerabilities and Exposures)
* CVE itu berpotensi membahayakan
* KEV itu diketahui sudah digunakan attacker
💀 Kenapa berbahaya?
Attacker bisa menjalankan kode di device korban cukup dengan membuat korban membuka page. Levelnya command di OS. Alias bisa buka file-file kita, curi foto dan video, hapus file, mencuri login password akun bank dan layanan finance lainnya, bahkan kalo mau attacker bisa download ransomeware atau backdoor dan dijalanin di device korban.
Semua itu, tanpa download, tanpa install, tanpa warning. Cukup buka halaman web yg disiapkan. 😐
⚠️ Bagaimana kita bisa kena?
Cuman 1x klik open page, biasanya dari malvertising (malicious advertising) atau link phishing. Cukup sesederhana itu.
Begitu klik dan page tujuan loading, kalau browser belum di-update, attacker bisa langsung masuk. Bisa juga paling cepat dia bikij otomasi ambil seluruh password yg tersimpan di device, serta session cookies. Korban nggak akan sadar, gw aja kagak mungkin sadar kalau gw nggak ngecek ketika itu berlangsung.
* Session cookies dicuri artinya attacker bisa login ke akun kamu, tanpa password.
🚨 Bugs dari software apa?
Browser berbasis Chromium: Chrome, Edge, Brave, Opera, Vivaldi, dll.
Mobile browser: Chrome dan Opera.
Juga berdampak ke: ChromeOS, Electron apps, Flutter (Skia), dan Debian (bookworm & trixie).
Safari nggak terdampak secara langsung dari kasus ini, tapi Apple juga baru keluarin patch celah lain di WebKit (CVE-2026-20643) yang juga bisa RCE (Remote Code Execution), risk level sama tingginya.
✅ Musti gimana?
Update browser.
Restart browser.
Selesai.
Selesai liburan, sebelum buka browser di PC kantor, jangan lupa update dulu.
Post summary
The message is an urgent patch alert for CVE‑2026‑3909 and CVE‑2026‑3910, emphasizing that they are actively exploited via web pages, and advises users to update browsers immediately.
🌐 CISA KEV: Two new Chrome vulnerabilities actively exploited (CVE-2026-3910, CVE-2026-3909)
Google Chrome V8 and Skia bugs allowing remote code execution via malicious web pages.
Every DIS contractor uses Chrome. Every Chrome instance is an attack surface.
Thread on what you need to know 👇
Post summary
CISA reports that two Chrome bugs (CVE‑2026‑3910 and CVE‑2026‑3909) are being actively exploited to achieve remote code execution via malicious web pages.