CVE-2026-3909
HIGH KEVGoogle Chrome < 146.0.7680.75 - Out-of-bounds Write in Skia via Crafted HTML Page
Title source: llmExploitation Summary
CVE-2026-3909 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 13, 2026. EIP tracks 3 public exploits from researchers including adminlove520, Hex0rc1st, anansi2safe.
AI-analyzed exploit summary This repository provides a detailed technical analysis and patch modifications for CVE-2026-3909, a Chromium vulnerability involving an out-of-bounds access in the Skia library's atlas handling. It includes debugging code and stack traces but does not contain a functional exploit.
Description
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Exploits (3)
This repository provides a detailed technical analysis and patch modifications for CVE-2026-3909, a Chromium vulnerability involving an out-of-bounds access in the Skia library's atlas handling. It includes debugging code and stack traces but does not contain a functional exploit.
This repository provides a detailed technical analysis and patch modifications for CVE-2026-3909, a vulnerability in Chromium's Skia library related to out-of-bounds access in the `GrDrawOpAtlas::hasID()` function. It includes patch files and debugging code to reliably trigger the vulnerability in a real Chromium environment.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H