HIGH
CVE-2026-3910
CVSS
8.8
KEV
Description
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
A vulnerability in Google's V8 JavaScript engine (used in Chrome/Chromium) allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The 'inappropriate implementation' flaw in V8 combined with malicious web content enables code execution within the browser's sandboxed environment.
Mitigation
Update Google Chrome to version 146.0.7680.75 or later. Organizations should ensure automatic updates are enabled or deploy the patched version through their endpoint management systems.
Weakness (CWE)
CWE-94
Code Injection
CWE-119
Memory Buffer Bounds Error
EPSS Score
2%
Probability of exploitation in next 30 days
79.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.