CVE-2026-3919Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-11: 1Mentions · 2026-03-12: 2Mentions · 2026-03-19: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-19: 103-1103-1203-19
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-122
Disclosure1General1
2026-03-191
Patch1
Full discourse4 posts
  • iototsecnews@iototsecnews
    Patch

    Google が Chrome 146 を正式リリース:リモート・コード実行などの 29 件の脆弱性を修正 https://iototsecnews.jp/2026/03/12/chrome-security-update-patch-for-29-vulnerabilities-that-allow-remote-code-execution/ 今回の Chrome のアップデートでは、プログラムが確保したメモリ領域に対する扱いの不備が主な原因となっています。特に CVE-2026-3913 では、割り当てられたサイズを超えてデータを書き込んでしまうヒープバッファ・オーバーフローが発生します。また、CVE-2026-3917/CVE-2026-3919 などで指摘された解放済みメモリ使用 (UAF) は、すでに不要として解放されたメモリ領域への不正なアクセスにより発生します。これらのメモリ管理の問題は、悪意の Web ページを閲覧するだけで、リモート・コード実行に至るなどの深刻な影響を招く可能性があるため、注意が必要です。 #Chrome #CVE20263916 #CVE20263917 #CVE20263918 #CVE20263919 #CVE20263921 #CVE20263922 #CVE20263923 #CVE20263924 #Google

    Post summary

    Google released Chrome 146, addressing 29 vulnerabilities—including CVE‑2026‑3913, CVE‑2026‑3917, and CVE‑2026‑3919—that enable remote code execution via memory‑management flaws such as heap buffer overflows and use‑after‑free. The article focuses on the patch announcement and technical details of the fixes.

    01000285
    484 followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-3919) https://vuldb.com/?id.350581

    Post summary

    The post announces a new Google Chrome vulnerability (CVE‑2026‑3919) but provides no detailed technical information, PoC, exploit, or patch details.

    00001214
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3919 - High Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a craf... https://www.thehackerwire.com/vulnerability/CVE-2026-3919/ https://t.co/1pVqPwfKJV

    Post summary

    The post announces a use‑after‑free vulnerability in Google Chrome extensions that could cause heap corruption, but does not mention active exploitation, a PoC, or a patch.

    0000046
    134 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3919 Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit he… https://www.cve.org/CVERecord?id=CVE-2026-3919

    Post summary

    A brief disclosure of CVE-2026-3919, identifying a use‑after‑free flaw in Chrome extensions impacting pre‑146.0.7680.71 builds, with no mention of exploitation, patch, or PoC.

    00000111
    56.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more