CVE-2026-3936Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-12); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-11: 1Mentions · 2026-03-12: 3Mentions · 2026-03-19: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-19: 103-1103-1203-19
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-123
Disclosure2Patch1
2026-03-191
Patch1
Full discourse5 posts
  • Emmanuel Nii Okai@engniiokai
    Patch

    🚨 Chrome 146 Security Alert Google patched 29 vulnerabilities, including CVE-2026-3936 (Use-After-Free in WebView). Key points: • Remote code execution possible via crafted web pages • Exploitable without user interaction (drive-by) • Could expose session data, credentials, or tokens • Update Chrome immediately to v146.0.7680.71+ Millions of users and apps are at risk. Don’t wait patch now. #CyberSecurity #ZeroDay #ThreatIntel #Infosec

    Post summary

    Google patched CVE-2026-3936 in Chrome 146, alerting users that a Use‑After‑Free in WebView could allow remote code execution via drive‑by pages; users are urged to update immediately to mitigate the risk.

    1101096
    718 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-3936) https://vuldb.com/?id.350611

    Post summary

    The post announces a newly disclosed Chrome CVE (CVE‑2026‑3936) with elevated criticality, but provides no details on exploitation methods, patches, or technical aspects.

    0000187
    2.1K followersView on X
  • WindowsForum@windowsforum
    Patch

    🔥 Edge admins: yet another “wait for Chromium to fix it” moment. Use-after-free in WebView means crashiness with a side of chaos—patch fast before attackers do your reboot for you. https://windowsforum.com/threads/cve-2026-3936-webview-use-after-free-edge-admins-need-fast-patch-action.405595/ #ChromiumWebview #MicrosoftEdgeSecurity #Cve20263936

    Post summary

    The post warns of a use‑after‑free flaw in Edge WebView, emphasizes the need for an immediate patch, and provides minimal technical details.

    000003
    1.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3936 - High Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severi... https://www.thehackerwire.com/vulnerability/CVE-2026-3936/ https://t.co/StLEg60s9Z

    Post summary

    CVE-2026-3936 is a use‑after‑free/heap corruption vulnerability in Google Chrome for Android (pre‑146.0.7680.71) that could be triggered via a crafted HTML page, but no PoC, patch, or active exploitation evidence is mentioned.

    0000046
    134 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3936 Use after free in WebView in Google Chrome on Android prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (… https://www.cve.org/CVERecord?id=CVE-2026-3936

    Post summary

    The statement discloses CVE‑2026‑3936 as a use‑after‑free vulnerability in Chrome WebView on Android that could allow remote heap corruption through crafted HTML, with no mention of PoC, exploit code, or patches.

    00000112
    56.7K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more