CVE-2026-3926
8.8Google · Chrome
An out of bounds read vulnerability exists in the V8 engine of Google Chrome, allowing remote attackers to perform unauthorized memory access via a crafted HTML page.
Executive summary
Google Chrome versions prior to 146.0.7680.71 are vulnerable to a high-severity memory access flaw that could allow remote attackers to compromise system data.
Vulnerability
This is an out of bounds read vulnerability (CWE-125) within the V8 JavaScript engine. A remote, unauthenticated attacker can trigger this flaw by enticing a user to navigate to a specifically crafted HTML page.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high level of severity. Successful exploitation could lead to information disclosure or potentially assist in further attacks against the browser process, resulting in significant data compromise or loss of system integrity.
Remediation
Immediate Action: Update all Google Chrome installations to version 146.0.7680.71 or later immediately.
Proactive Monitoring: Monitor network traffic for suspicious redirects and review browser security logs for anomalies following the application of the update.
Compensating Controls: Ensure that browser security settings are configured to block untrusted scripts and utilize endpoint protection software that can detect malicious memory access patterns.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the prevalence of Chrome in enterprise environments, this vulnerability poses a substantial risk. IT administrators must prioritize the distribution of the 146.0.7680.71 update across all managed endpoints to ensure protection against potential exploitation of the V8 engine.