CVE-2026-3909

HIGH KEV

Google Chrome < 146.0.7680.75 - Out-of-bounds Write in Skia via Crafted HTML Page

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-3909 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 13, 2026. EIP tracks 3 public exploits from researchers including adminlove520, Hex0rc1st, anansi2safe.

AI-analyzed exploit summary This repository provides a detailed technical analysis and patch modifications for CVE-2026-3909, a Chromium vulnerability involving an out-of-bounds access in the Skia library's atlas handling. It includes debugging code and stack traces but does not contain a functional exploit.

Description

Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

Exploits (3)

github WRITEUP 4 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2026/CVE-2026-3909

This repository provides a detailed technical analysis and patch modifications for CVE-2026-3909, a Chromium vulnerability involving an out-of-bounds access in the Skia library's atlas handling. It includes debugging code and stack traces but does not contain a functional exploit.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Theoretical
Target: Chromium (version 146.0.7680.71 and earlier)
No auth needed
Prerequisites: Vulnerable Chromium build · Patch application · Debugging environment
devstral-2 · analyzed May 10, 2026 Full analysis →
nomisec WRITEUP 1 stars
by anansi2safe · poc
https://github.com/anansi2safe/CVE-2026-3909-PoC

This repository provides a detailed technical analysis and patch modifications for CVE-2026-3909, a vulnerability in Chromium's Skia library related to out-of-bounds access in the `GrDrawOpAtlas::hasID()` function. It includes patch files and debugging code to reliably trigger the vulnerability in a real Chromium environment.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Chromium Browser (version 146.0.7680.71 and earlier)
No auth needed
Prerequisites: Vulnerable version of Chromium · Ability to apply patches to Chromium source code · Access to build and run Chromium with custom patches
devstral-2 · analyzed Apr 11, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.0045
EPSS Percentile 64.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2026-03-13
VulnCheck KEV 2026-03-13
ENISA EUVD EUVD-2026-11734
CWE
CWE-787
Status published
Products (2)
google/chrome < 146.0.7680.75
Google/Chrome 146.0.7680.75
Published Mar 13, 2026
KEV Added Mar 13, 2026
Tracked Since Mar 14, 2026