CVE-2026-3913Patch(apple / chrome)

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch apple chrome systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

5.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 10 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • Peaked 5d ago at 3 mentions (2026-03-13); latest day: 1
  • 10 total mentions across 8 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline10 mentions / 8d
01223Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-13: 3Mentions · 2026-03-15: 1Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-19: 1Mentions · 2026-03-26: 1Active Exploitation · 2026-03-16: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 3Technical Details · 2026-03-15: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-19: 103-1103-1203-1303-1503-1603-1703-1903-26
Signal classification3 categories
Patch
550.0%
Disclosure
440.0%
Active Exploitation
110.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-121
Patch1
2026-03-133
Disclosure2Patch1
2026-03-151
Patch1
2026-03-161
Active Exploitation1
2026-03-171
Disclosure1
2026-03-191
Patch1
2026-03-261
Patch1
Full discourse10 posts
  • iototsecnews@iototsecnews
    Patch

    Google が Chrome 146 を正式リリース:リモート・コード実行などの 29 件の脆弱性を修正 https://iototsecnews.jp/2026/03/12/chrome-security-update-patch-for-29-vulnerabilities-that-allow-remote-code-execution/ 今回の Chrome のアップデートでは、プログラムが確保したメモリ領域に対する扱いの不備が主な原因となっています。特に CVE-2026-3913 では、割り当てられたサイズを超えてデータを書き込んでしまうヒープバッファ・オーバーフローが発生します。また、CVE-2026-3917/CVE-2026-3919 などで指摘された解放済みメモリ使用 (UAF) は、すでに不要として解放されたメモリ領域への不正なアクセスにより発生します。これらのメモリ管理の問題は、悪意の Web ページを閲覧するだけで、リモート・コード実行に至るなどの深刻な影響を招く可能性があるため、注意が必要です。 #Chrome #CVE20263916 #CVE20263917 #CVE20263918 #CVE20263919 #CVE20263921 #CVE20263922 #CVE20263923 #CVE20263924 #Google

    Post summary

    Google released Chrome 146, patching 29 vulnerabilities—including CVE‑2026‑3913’s heap buffer overflow and UAF flaws—that could allow remote code execution via malicious web pages.

    01000285
    484 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Google ❗ CVE-2026-3915 ❗ CVE-2026-3914 ❗ CVE-2026-3913 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-google-6/ https://t.co/J0fPyRVrJD

    Post summary

    The post lists three Google product CVEs and provides links for additional information, but offers no technical details, patch info, or evidence of exploitation.

    00001114
    6.6K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Active Exploitation

    Heads-up, Linux community. There’s a nasty #Chromium vulnerability in the wild targeting #Fedora 42. CVE-2026-3913 allows RCE via a heap overflow in WebML. Read more: 👉 https://tinyurl.com/25rve7hd #Security https://t.co/gXUQ3VwVRL

    Post summary

    The tweet announces that CVE-2026-3913, a heap‑overflow RCE in Chromium’s WebML, is actively exploited in the wild against Fedora 42.

    0001089
    1.4K followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 146.0.7680.71 (Linux) および 146.0.7680.71/72 (Windows および Mac) をリリース. CVE ベースで Critical 1 件 ・CVE-2026-3913 High 11 件,これらを含む全 29 件の脆弱性に対処. https://x.com/kawn2020/status/2033064584211480904

    Post summary

    Google released a Chrome 146 security update that fixed 29 vulnerabilities, including the critical CVE‑2026‑3913, with no PoC or active exploitation details disclosed.

    100001.0K
    89 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chromeos Google が ChromeOS version 16581.42.0 (Browser version 146.0.7680.169) をリリース. CVE ベースで Critical 1 件 ・CVE-2026-3913 および High 11 件を含む全 24 件の脆弱性に対処. https://x.com/kawn2020/status/2037088696747659473

    Post summary

    Google released a ChromeOS update that patches CVE-2026-3913 and 23 other high‑severity vulnerabilities, addressing a total of 24 bugs.

    0000056
    87 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3913 - High Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Cri... https://www.thehackerwire.com/vulnerability/CVE-2026-3913/ https://t.co/9Lk4HlxtHR

    Post summary

    The post announces the discovery of CVE-2026‑3913, a high‑severity heap buffer overflow in Chrome's WebML component that may allow remote exploitation through a crafted HTML page. No PoC, exploit code, or mitigation details are provided.

    0000042
    134 followersView on X
  • securityrss.ai@securityRSS
    Patch

    Google released Chrome version 146.0.7680.71, addressing 29 vulnerabilities across Windows, Mac, and Linux. The most critical, CVE-2026-3913, is a heap buffer overflow in the WebML component, allowing remote code execution. https://cybersecuritynews.com/chrome-security-update-29-vulnerabilities/

    Post summary

    The article announces a Chrome update that patches 29 vulnerabilities, including the critical CVE-2026-3913, which is a heap buffer overflow permitting remote code execution.

    0000072
    78 followersView on X
  • Arnaud Mercier - #Entrepreneur@arnaudmercier
    Disclosure

    Google has confirmed CVE-2026-3913, a critical security vulnerability in Chrome. one that could enable a remote code execution attack simply by visiting a web page. https://www.forbes.com/sites/daveywinder/2026/03/12/critical-google-chrome-security-bug-visiting-web-page-executes-attack/

    Post summary

    Google confirms CVE-2026-3913 as a critical Chrome vulnerability that allows remote code execution simply by visiting a malicious webpage; no PoC, exploit, or patch details are provided.

    0000056
    37.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Google releases Chrome 146, fixing 29 vulnerabilities including a critical heap buffer overflow in WebML (CVE-2026-3913). Update your browser immediately. #Chrome146 #GoogleChrome #CVE20263913 #CyberSecurity #PatchAlert #InfoSec #BugBounty #Vulnerability https://securityonline.info/chrome-146-arrives-with-29-security-fixes-critical-webml-flaw-discovered/ https://t.co/eSaiAchpsb

    Post summary

    Google’s Chrome 146 update addresses 29 vulnerabilities, including a critical heap buffer overflow in WebML (CVE‑2026‑3913). Users are advised to install the patch immediately.

    00000309
    10.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3913 Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromiu… https://www.cve.org/CVERecord?id=CVE-2026-3913

    Post summary

    The entry reports a newly disclosed heap buffer overflow in Google Chrome’s WebML component, affecting versions prior to 146.0.7680.71 and potentially exploitable via crafted HTML pages.

    00000123
    56.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more