Google patches two Chrome zero-days under active attack. Update now

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Google has released an emergency out-of-band Chrome update patching two actively exploited zero-day vulnerabilities. CVE-2026-3909 is an out-of-bounds write in Skia (Chrome's 2D graphics library) that can corrupt memory and enable code execution, while CVE-2026-3910 is an inappropriate implementation flaw in the V8 JavaScript engine allowing arbitrary code execution inside the V8 sandbox. Both require only a user to visit a malicious webpage. The patched version is 146.0.7680.75/76. Users should update immediately via Settings > About Chrome and restart the browser.

3m read timeFrom securityboulevard.com
Post cover image
Table of contents
How to update ChromeTechnical detailsHow to stay safe

Sort: