CVE-2026-3910Active Exploitation(apple / chrome)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 42 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

9.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-27. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94CWE-119

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 109 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 157 mentions across 30 observed days

What's happening

  • Active exploitation reported across 109 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 97 signals
  • Technical details provided in 93 signals
  • General: 17 classified signals
  • Peaked 28d ago at 42 mentions (2026-03-13); latest day: 2
  • 157 total mentions across 30 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline157 mentions / 30d
011213242Mentions · 2026-03-12: 4Mentions · 2026-03-13: 42Mentions · 2026-03-14: 25Mentions · 2026-03-15: 18Mentions · 2026-03-16: 17Mentions · 2026-03-17: 8Mentions · 2026-03-18: 1Mentions · 2026-03-19: 2Mentions · 2026-03-20: 3Mentions · 2026-03-21: 5Mentions · 2026-03-22: 4Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Mentions · 2026-03-26: 4Mentions · 2026-03-27: 1Mentions · 2026-04-01: 1Mentions · 2026-04-06: 1Mentions · 2026-04-15: 1Mentions · 2026-04-17: 2Mentions · 2026-05-02: 1Mentions · 2026-05-03: 1Mentions · 2026-05-15: 2Mentions · 2026-06-06: 1Mentions · 2026-06-09: 1Mentions · 2026-06-12: 2Mentions · 2026-06-26: 1Mentions · 2026-07-08: 2Mentions · 2026-07-17: 1Mentions · 2026-09-06: 1Mentions · 2026-09-09: 2PoC Mentioned / Linked · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-26: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-06-12: 1PoC Mentioned / Linked · 2026-07-08: 1Exploit Tool / Code · 2026-06-12: 1Exploit Tool / Code · 2026-07-08: 1Active Exploitation · 2026-03-12: 2Active Exploitation · 2026-03-13: 30Active Exploitation · 2026-03-14: 21Active Exploitation · 2026-03-15: 14Active Exploitation · 2026-03-16: 10Active Exploitation · 2026-03-17: 5Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-19: 2Active Exploitation · 2026-03-20: 3Active Exploitation · 2026-03-21: 4Active Exploitation · 2026-03-22: 2Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-03-26: 2Active Exploitation · 2026-04-01: 1Active Exploitation · 2026-04-15: 1Active Exploitation · 2026-04-17: 2Active Exploitation · 2026-05-15: 1Active Exploitation · 2026-06-06: 1Active Exploitation · 2026-06-09: 1Active Exploitation · 2026-09-06: 1Active Exploitation · 2026-09-09: 2Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 29Patch / Workaround · 2026-03-14: 13Patch / Workaround · 2026-03-15: 9Patch / Workaround · 2026-03-16: 12Patch / Workaround · 2026-03-17: 5Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-19: 2Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-21: 5Patch / Workaround · 2026-03-22: 4Patch / Workaround · 2026-03-23: 2Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-06-09: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-07-17: 1Patch / Workaround · 2026-09-06: 1Patch / Workaround · 2026-09-09: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 26Technical Details · 2026-03-14: 12Technical Details · 2026-03-15: 9Technical Details · 2026-03-16: 9Technical Details · 2026-03-17: 6Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-21: 3Technical Details · 2026-03-22: 4Technical Details · 2026-03-23: 1Technical Details · 2026-03-24: 1Technical Details · 2026-03-26: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 2Technical Details · 2026-05-02: 1Technical Details · 2026-05-15: 2Technical Details · 2026-06-06: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-08: 2Technical Details · 2026-09-06: 1Technical Details · 2026-09-09: 203-1203-1503-1803-2103-2404-0104-1705-1506-1207-1709-09
Signal classification6 categories
Active Exploitation
8151.6%
Patch
4126.1%
General
1710.8%
Disclosure
159.6%
PoC
21.3%
False Positive
10.6%
Referenced assets86 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-124
Active Exploitation1Disclosure1General1Patch1
2026-03-1342
Active Exploitation21Disclosure7General3Patch11
2026-03-1425
Active Exploitation15Disclosure2False Positive1General1Patch6
2026-03-1518
Active Exploitation12Disclosure2General2Patch2
2026-03-1617
Active Exploitation7General3Patch7
2026-03-178
Active Exploitation5Disclosure1Patch2
2026-03-181
Active Exploitation1
2026-03-192
Active Exploitation2
2026-03-203
Active Exploitation2Patch1
2026-03-215
Active Exploitation2Patch3
2026-03-224
Active Exploitation1Patch3
2026-03-232
Active Exploitation1Patch1
2026-03-241
Active Exploitation1
2026-03-264
Active Exploitation2General2
2026-03-271
Patch1
2026-04-011
Patch1
2026-04-061
General1
2026-04-151
Active Exploitation1
2026-04-172
Active Exploitation2
2026-05-021
General1
2026-05-031
General1
2026-05-152
Active Exploitation1Disclosure1
2026-06-061
Disclosure1
2026-06-091
Active Exploitation1
2026-06-122
General1PoC1
2026-06-261
Patch1
2026-07-082
General1PoC1
2026-07-171
Patch1
2026-09-061
Active Exploitation1
2026-09-092
Active Exploitation2
Full discourse20 posts
  • RewriteLab@RewriteLab
    PoC

    We published a new research article on the Chromium 146 Renderer Process! In this article, we start from the CVE-2026-3910 Maglev write barrier elision bug and walk through the full exploit chain: building a V8 heap R/W primitive via a GC-induced UAF, achieving an out-of-sandbox read using WebAssembly internals, abusing JSPI UAF and StackMemory / JumpBuffer, and ultimately reaching renderer process RCE. Our goal was to provide a structured explanation of how modern V8 exploitation works in practice, from compiler-level bug analysis to sandbox-boundary primitives and final code execution. Huge thanks to our team member @m411k_ for conducting this research! Check out the PoC! Full article: https://research.rewritelab.org/2026/06/11/%5BENG%5D%20Pwning%20Chromium%20146%20Renderer%20Process/

    Post summary

    Researchers present the complete exploit chain for CVE‑2026‑3910, including a PoC leading to renderer‑process RCE, without evidence of real‑world exploitation or a fix.

    135017110612.6K
    590 followersView on X
  • Zero Day Engineering@zerodayalpha
    Active Exploitation

    ⚡️0-Day Alert: Google Chrome RCE + EoP in the wild • CVE-2026-3910: v8 Maglev JIT incorrect write barrier elimination for Smi representation in Phi edge cases => UaF or memory corruption Impact: remote ACE in renderer via JavaScript code. Same structural pattern invariant as seen in a recent WebKit jsc bug. • CVE-2026-3909: Skia glyph cache key collision to out-of-bounds write in GPU process Impact: at least a partial (full on some platforms) Sandbox Escape primitive. Potentially reachable remotely via renderer media formats. In the specific exploit it was likely pushed directly to IPC from a compromised renderer via CVE-2026-3910. Both bugs patched since Chrome 146.0.7680.80 for Windows/Mac and 146.0.7680.80 for Linux

    Post summary

    The post reports active exploitation of two Chrome CVEs, outlines the technical details and impact, and confirms patches are available.

    132117210524.2K
    10.6K followersView on X
  • Hermes Tool@Hermes_tooll
    Active Exploitation

    ⚡️0-Day Alert: Google Chrome RCE + EoP in the wild • CVE-2026-3910: v8 Maglev JIT incorrect write barrier elimination for Smi representation in Phi edge cases => UaF or memory corruption Impact: remote ACE in renderer via JavaScript code. Same structural pattern invariant as seen in a recent WebKit jsc bug. • CVE-2026-3909: Skia glyph cache key collision to out-of-bounds write in GPU process Impact: at least a partial (full on some platforms) Sandbox Escape primitive. Potentially reachable remotely via renderer media formats. In the specific exploit it was likely pushed directly to IPC from a compromised renderer via CVE-2026-3910. Both bugs patched since Chrome 146.0.7680.80 for Windows/Mac and 146.0.7680.80 for Linux

    Post summary

    The text confirms that CVE-2026-3910 and CVE-2026-3909 have been actively exploited in the wild, delivering remote code execution and sandbox escape in Google Chrome; patches have been released in Chrome 146.0.7680.80.

    02701104710.6K
    3.3K followersView on X
  • Brave@brave
    General

    @Ajmah5 Sure thing! It's these two: CVE-2026-3909: https://cve.org/CVERecord?id=CVE-2026-3909 CVE-2026-3910: https://www.cve.org/CVERecord?id=CVE-2026-3910

    Post summary

    The message simply lists two CVE identifiers with links to their records, providing no further context or technical information.

    11081613.7K
    401.4K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Google Skia out-of-bounds write vulnerability CVE-2026-3909 & Google Chromium V8 unspecified vulnerability CVE-2026-3910 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/bjukrv3vvf

    Post summary

    The tweet announces that CVE‑2026‑3909 and CVE‑2026‑3910 are now in DHS’s KEV Catalog, indicating active exploitation, but no PoC, exploit code, or patch information is included.

    21523057.0K
    292.8K followersView on X
  • xvonfers@xvonfers
    Active Exploitation

    (CVE-2026-3910)[491410818][maglev]Inappropriate implementation(Phi untagging issues), exploited ITW https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html https://chromium-review.googlesource.com/c/v8/v8/+/7653638 Reported by Google

    Post summary

    CVE-2026-3910, a phi-untagging implementation flaw, has been actively exploited in the wild and has already been addressed in Google's Chrome release notes.

    24126158.9K
    4.9K followersView on X
  • Aquads.xyz@_Aquads_
    Active Exploitation

    Google has released emergency updates to patch multiple actively exploited zero-day vulnerabilities in Chrome in early 2026, including CVE-2026-3909 (Skia out-of-bounds write) and CVE-2026-3910 (V8 inappropriate implementation). These critical flaws allow remote attackers to execute code via crafted websites, affecting desktop and mobile users. Update immediately to version 146.0.7680+. BleepingComputer BleepingComputer +3 Recent & Active Chrome Exploits (2025-2026) March 2026 (CVE-2026-3909/3910): Emergency patches for two zero-days, one in the Skia graphics library and another in the V8 JavaScript engine [3, BleepingComputer]. February 2026 (CVE-2026-2441): The first actively exploited zero-day of 2026 was patched in February, targeting Chrome, Android, and ChromeOS. February 2026 (CSS Sandbox Escape): A critical vulnerability in the CSS engine was reported to allow sandbox escapes, requiring immediate extension auditing and browser updates [2, Instagram]. December 2025 (CVE-2025-14174): An out-of-bounds memory access vulnerability in ANGLE was exploited, prompting urgent CISA action [12, The Hacker News]. September-November 2025 (CVE-2025-10585): A type confusion vulnerability in the V8 engine was actively exploited in the wild [7, YouTube]. YouTube YouTube +4 Vulnerability Types and Impact V8 Engine Vulnerabilities: The V8 JavaScript/WebAssembly engine is a frequent target for "type confusion" or "inappropriate implementation" bugs, allowing attackers to escape the browser sandbox. Out-of-Bounds (OOB) Write/Memory Access: Flaws in components like Skia or ANGLE allow attackers to write data outside intended memory areas, resulting in crashes or code execution. Remote Code Execution (RCE): Many of these exploits permit attackers to execute arbitrary code on the victim's machine, allowing them to steal data or install malware. CIS Center for Internet Security CIS Center for Internet Security +4 How to Protect Yourself Update Now: Go to chrome://settings/help to force an update to the latest version. Restart Chrome: Patches are only applied after restarting the browser. Check Extensions: Review installed extensions to ensure they are not malicious, as some attacks target browser security, per Instagram. Automatic Updates: Keep automatic updates enabled for your OS and browser

    Post summary

    Google issued emergency patches for two actively exploited zero‑day Chrome vulnerabilities, urging immediate updates to prevent remote code execution.

    791143327
    686 followersView on X
  • xvonfers@xvonfers
    Active Exploitation

    (CVE-2026-3910)[491410818][maglev] also exploited in v8ctf(RCE) + 483092905/485784597(v8sbx escape)

    Post summary

    CVE‑2026‑3910 is being actively exploited in the wild, with proof‑of‑concept RCE and sandbox escape reported in v8ctf and related references.

    03015132.8K
    5.0K followersView on X
  • _SiCk@encrypted_past
    Disclosure

    More to the point. CVE-2025-9132 - OOB write CVE-2025-12036 - inappropriate implementation CVE-2025-13224 - type confusion (CVSS 8.8) CVE-2025-10585 - type confusion CVE-2025-13223 - type confusion (CVSS 8.8) CVE-2026-3910 - (CVSS 8.8, CISA KEV) Fuck v8.

    Post summary

    The brief note lists several 2025–2026 CVEs with their types, CVSS scores, and identifies CVE‑2026‑3910 as a CISA Key Exploit Vulnerability, indicating it's a disclosed vulnerability likely being exploited.

    0222142.6K
    2.7K followersView on X
  • xvonfers@xvonfers
    General

    (CVE-2026-3910)[491410818][maglev] https://chromium-review.googlesource.com/c/v8/v8/+/7604255 https://t.co/Euy6MK2z0E

    Post summary

    The tweet simply cites CVE‑2026‑3910 and provides a link to a Chromium review commit, offering no further context or details about the vulnerability.

    0101962.4K
    4.9K followersView on X
  • Barnacules Nerdgasm@Barnacules
    Patch

    Make sure you're on the latest version of Chrome or any Chromium based browser! Please share this everywhere! 🤗 You can get more information on the vulnerability @ https://app.opencve.io/cve/CVE-2026-3910

    Post summary

    The message urges users to update to the latest Chrome versions for CVE‑2026‑3910, referencing the CVE page but providing no technical details, PoC, or exploit information.

    2701411.2K
    101.0K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/13追加) 🛡️No.1542 CVE-2026-3909 Google Skia Out-of-Bounds Write Vulnerability ===================================== ✅概要 ・深刻度:高⚠️ 8.8 (CVSS Base) / Google Chrome ・種別:境界外書き込み (CWE-787) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H ・影響バージョン:Google Chrome 146.0.7680.75 未満 Google Chrome が使用するSkia 2Dグラフィックライブラリにおける境界外書き込みの脆弱性。 細工された HTML ページを開かせることでメモリ破損が発生し、ブラウザクラッシュや任意コード実行につながる可能性がある。 --- ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 --- ✅攻撃前提条件 ・ユーザーが 攻撃者の用意したページを閲覧すること ・脆弱な Chrome バージョンを利用していること --- ✅悪用時影響 ・ブラウザメモリ破損 ・任意コード実行 ・マルウェア感染 ・端末侵害の初期侵入点 --- ✅悪用事例等に関する情報 ・PoC/Exploit:公開情報なし ・ITW:あり(ゼロデイとして悪用確認) --- ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-3909 https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html https://thehackernews.com/2026/03/google-fixes-two-chrome-zero-days.html https://bleepingcomputer.com/news/google/google-fixes-two-new-chrome-zero-days-exploited-in-attacks/ 🛡️No.1543 CVE-2026-3910 Google Chromium V8 Unspecified Vulnerability ===================================== ✅概要 ・深刻度:高⚠️ 8.8 (CVSS Base) / NVD ・種別:不適切な実装 (CWE-94 / Code Injection) ・CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H ・影響バージョン:Google Chrome 146.0.7680.75 未満Google Chrome の V8 JavaScript / WebAssembly エンジンにおける実装不備の脆弱性。 細工された HTML ページを開くことで、攻撃者がブラウザサンドボックス内で任意コードを実行できる可能性がある。 --- ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 --- ✅攻撃前提条件 ・ユーザーが 攻撃者の用意したページを閲覧すること ・脆弱な Chrome バージョンを使用していること --- ✅悪用時影響 ・ブラウザ内での任意コード実行 ・サンドボックス回避の足掛かり ・マルウェア感染 ・情報窃取 --- ✅悪用事例等に関する情報 ・PoC/Exploit:公開情報なし ・ITW:あり(ゼロデイとして悪用確認) --- ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-3910 CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/13/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirms that CVE‑2026‑3909 and CVE‑2026‑3910 are actively exploited in the wild as zero‑day attacks, with detailed vulnerability data provided but no public PoC or fix detailed.

    0801415.9K
    42.7K followersView on X
  • Md. Najeeb Hussain@mnh_18
    Patch

    Android System WebView June 2026 update fixes 4 serious vulnerabilities. Here's what they were. Android System WebView (MWebView 2026.06.13): Besides CVE-2026-3910, addresses three other high-severity issues: an integer overflow in WebGL, a use-after-free in the speech synthesis API, and a DOM cross-origin bypass affecting offline service workers. The 4 WebView vulnerabilities fixed explained in plain English: 🔴 CVE-2026-3910 (Critical): ▪ Any website could potentially execute code on your phone ▪ The type of vulnerability state-sponsored hackers exploit for targeted attacks 🟠 INTEGER OVERFLOW IN WEBGL: ▪ Viewing specially crafted 3D web content → potential code execution ▪ Affects: any app using WebGL (Instagram, games with web views) 🟠 USE-AFTER-FREE IN SPEECH SYNTHESIS: ▪ Using text-to-speech in a browser → memory corruption possible ▪ Could allow attacker to read private memory regions 🟠 DOM CROSS-ORIGIN BYPASS: ▪ A website could read content from another website in offline service workers ▪ Your cached offline banking app → potentially readable by a malicious site HOW TO UPDATE ANDROID SYSTEM WEBVIEW: Google Play Store → search "Android System WebView" → Update This is NOT automatic on all devices. You must manually update it from the Play Store. Every app that renders web content on your Galaxy uses WebView. That's: Instagram · WhatsApp web preview · banking apps · news apps. Update it. Now. 🔐 #AndroidWebView #Samsung #Security #CVE #Android

    Post summary

    Google released an Android System WebView 2026.06.13 update that fixes four high‑severity vulnerabilities, including CVE-2026-3910, and urges users to manually update the app via the Play Store.

    0101431.4K
    713 followersView on X
  • うみれおん(Kaito Udagawa)@umireon
    General

    すみません、引用ポストを確認しました。これは元ポストの方の書き方が悪いですね。 対象となったCVEの登録情報を参照するとわかるのですが、このゼロデイ攻撃はWindows、Mac、Linux上のPC版Chromeが対象であり、そもそもAndroidやiPhoneのChromeでは報告されていない脆弱性のようです。 アップデートし続けることは良いことですし、未知のスマホ版Chromeの脆弱性があるかもしれないので、アップデートの啓蒙については一切否定しない一方で、関係ない行動が今回のセキュリティインシデントの対策につながると発信してしまうのも問題があると考えておりますので、今回は引用をつけさせていただきました。 https://app.opencve.io/cve/CVE-2026-3909 https://app.opencve.io/cve/CVE-2026-3910

    Post summary

    The post links to CVE-2026-3909 and CVE-2026-3910, noting they target Chrome on desktop platforms, but provides no PoC, exploit code, patches, or evidence of active exploitation, making it a general reference.

    110362.6K
    1.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Google releases an emergency Chrome update to patch two actively exploited zero-day vulnerabilities (CVE-2026-3909 & CVE-2026-3910). Update immediately. #ChromeZeroDay #GoogleChrome #CVE #CyberSecurity #InfoSec #PatchAlert #BrowserSecurity #ZeroDay https://securityonline.info/double-zero-day-threat-emergency-chrome-update-patches-actively-exploited-skia-and-v8-flaws/ https://t.co/RwRjaDvyBc

    Post summary

    Google issued an emergency Chrome update to fix CVE‑2026‑3909 and CVE‑2026‑3910, which are actively exploited zero‑day vulnerabilities.

    11036611
    10.6K followersView on X
  • Marc@Marc296134
    Active Exploitation

    Cette faille Chrome est réelle — deux zero-days (CVE-2026-3909 et CVE-2026-3910) activement exploités, corrigés le 16 mars dans Chrome 146.0.7680.75. Mais c’est aussi le rappel parfait d’une habitude dangereuse : stocker ses mots de passe dans Chrome. Si la faille est exploitée avant la mise à jour, ils sont tous exposés. J’explique pourquoi et comment s’en protéger → http://webologie.me/mots-de-passe-navigateur-danger/

    Post summary

    Two Chrome zero‑day CVEs (CVE‑2026‑3909, CVE‑2026‑3910) were reported as actively exploited and patched on March 16, with advice to avoid storing passwords in the browser.

    20041323
    2.9K followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🌐 CISA KEV: Two new Chrome vulnerabilities actively exploited (CVE-2026-3910, CVE-2026-3909) Google Chrome V8 and Skia bugs allowing remote code execution via malicious web pages. Every DIB contractor uses Chrome. Every Chrome instance is an attack surface. Thread on what you need to know 👇

    Post summary

    CISA KEV reports that CVE-2026-3910 and CVE-2026-3909 are actively exploited in Chrome, with bugs in V8 and Skia enabling remote code execution through malicious web pages.

    50010123
    331 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2026-41940 3 - CVE-2026-3910 4 - CVE-2024-20359 5 - CVE-2024-20353 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without providing any additional technical, exploit, or mitigation information.

    01031255
    1.7K followersView on X
  • Console Age@console_age
    Patch

    🚨 URGENT PATCH 🚨 Versi Indo dan lebih “awam friendly” Dua bugs-nya Chrome, CVE-2026-3910 & CVE-2026-3909, lagi gencar dieksploitasi oleh attacker/hacker. CISA sudah memasukkan ini ke KEV catalog (Known Exploited Vulnerabilities) alias naik kelas dari CVE (Common Vulnerabilities and Exposures) * CVE itu berpotensi membahayakan * KEV itu diketahui sudah digunakan attacker 💀 Kenapa berbahaya? Attacker bisa menjalankan kode di device korban cukup dengan membuat korban membuka page. Levelnya command di OS. Alias bisa buka file-file kita, curi foto dan video, hapus file, mencuri login password akun bank dan layanan finance lainnya, bahkan kalo mau attacker bisa download ransomeware atau backdoor dan dijalanin di device korban. Semua itu, tanpa download, tanpa install, tanpa warning. Cukup buka halaman web yg disiapkan. 😐 ⚠️ Bagaimana kita bisa kena? Cuman 1x klik open page, biasanya dari malvertising (malicious advertising) atau link phishing. Cukup sesederhana itu. Begitu klik dan page tujuan loading, kalau browser belum di-update, attacker bisa langsung masuk. Bisa juga paling cepat dia bikij otomasi ambil seluruh password yg tersimpan di device, serta session cookies. Korban nggak akan sadar, gw aja kagak mungkin sadar kalau gw nggak ngecek ketika itu berlangsung. * Session cookies dicuri artinya attacker bisa login ke akun kamu, tanpa password. 🚨 Bugs dari software apa? Browser berbasis Chromium: Chrome, Edge, Brave, Opera, Vivaldi, dll. Mobile browser: Chrome dan Opera. Juga berdampak ke: ChromeOS, Electron apps, Flutter (Skia), dan Debian (bookworm & trixie). Safari nggak terdampak secara langsung dari kasus ini, tapi Apple juga baru keluarin patch celah lain di WebKit (CVE-2026-20643) yang juga bisa RCE (Remote Code Execution), risk level sama tingginya. ✅ Musti gimana? Update browser. Restart browser. Selesai. Selesai liburan, sebelum buka browser di PC kantor, jangan lupa update dulu.

    Post summary

    The message is an urgent patch alert for CVE‑2026‑3909 and CVE‑2026‑3910, emphasizing that they are actively exploited via web pages, and advises users to update browsers immediately.

    03020348
    1.4K followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🌐 CISA KEV: Two new Chrome vulnerabilities actively exploited (CVE-2026-3910, CVE-2026-3909) Google Chrome V8 and Skia bugs allowing remote code execution via malicious web pages. Every DIS contractor uses Chrome. Every Chrome instance is an attack surface. Thread on what you need to know 👇

    Post summary

    CISA reports that two Chrome bugs (CVE‑2026‑3910 and CVE‑2026‑3909) are being actively exploited to achieve remote code execution via malicious web pages.

    5000086
    331 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more