HIGH

CVE-2026-3910

Google Chrome 2026-03-13 CVSS v3.1
CVSS
8.8
KEV

Description

Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Summary dbcve.org

A vulnerability in Google's V8 JavaScript engine (used in Chrome/Chromium) allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. The 'inappropriate implementation' flaw in V8 combined with malicious web content enables code execution within the browser's sandboxed environment.

Mitigation

Update Google Chrome to version 146.0.7680.75 or later. Organizations should ensure automatic updates are enabled or deploy the patched version through their endpoint management systems.

Weakness (CWE)

CWE-94 Code Injection
CWE-119 Memory Buffer Bounds Error

EPSS Score

2%
Probability of exploitation in next 30 days
79.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE