{"id":11323,"date":"2026-03-13T10:04:29","date_gmt":"2026-03-13T10:04:29","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/13\/chrome-zero-day-vulnerabilities-actively-exploited-in-the-wild-to-execute-malicious-code\/"},"modified":"2026-03-13T10:04:29","modified_gmt":"2026-03-13T10:04:29","slug":"chrome-zero-day-vulnerabilities-actively-exploited-in-the-wild-to-execute-malicious-code","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/13\/chrome-zero-day-vulnerabilities-actively-exploited-in-the-wild-to-execute-malicious-code\/","title":{"rendered":"Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code"},"content":{"rendered":"<p>    Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Google has released an urgent security update for its Chrome browser after confirming that two high-severity<a href=\"https:\/\/cybersecuritynews.com\/chrome-zero-day-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\"> zero-day vulnerabilities<\/a> are being actively exploited in the wild.<\/p>\n<p>The stable channel has been updated to version 146.0.7680.75\/76 for Windows and macOS, and 146.0.7680.75 for Linux, with the rollout expected to reach users over the coming days and weeks.<\/p>\n<p>Both vulnerabilities were reported internally by Google\u2019s own security team on March 10, 2026, and carry a High severity rating, underscoring the seriousness of the threat to Chrome users worldwide.<\/p>\n<h3 class=\"wp-block-heading\" id=\"cve-2026-3909-out-of-bounds-write-in-skia\"><strong>CVE-2026-3909: Out-of-Bounds Write in Skia<\/strong><\/h3>\n<p>The first flaw, tracked as CVE-2026-3909, is an out-of-bounds write vulnerability residing in Skia, the open-source 2D graphics engine that powers Chrome\u2019s rendering pipeline.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/out-of-bounds-read-and-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">Out-of-bounds write bugs<\/a> are particularly dangerous because they allow attackers to overwrite adjacent memory regions, potentially enabling arbitrary code execution or application crashes.<\/p>\n<p>When exploited in a browser context, this type of vulnerability can be leveraged to escape sandbox protections and execute malicious code on the victim\u2019s system.<\/p>\n<h3 class=\"wp-block-heading\" id=\"cve-2026-3910-inappropriate-implementation-in-v8\"><strong>CVE-2026-3910: Inappropriate Implementation in V8<\/strong><\/h3>\n<p>The second vulnerability, CVE-2026-3910, involves an inappropriate implementation in V8, Chrome\u2019s high-performance JavaScript and WebAssembly engine.<\/p>\n<p>Flaws in V8 are a persistent target for threat actors because JavaScript is constantly executed during normal web browsing, creating abundant exploitation opportunities. An attacker could craft a malicious webpage that, when visited, triggers the flaw to execute code in the context of the browser process.<\/p>\n<p><a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop_12.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google has explicitly confirmed<\/a> that exploits for both CVE-2026-3909 and CVE-2026-3910 exist in the wild, making this a critical update for individuals and organizations alike.<\/p>\n<p>Technical details about the bugs and any associated bug tracker entries remain restricted until a significant portion of the user base has applied the patch, a standard practice to prevent further exploitation before systems are protected.<\/p>\n<h2 class=\"wp-block-heading\" id=\"immediate-action-recommended\"><strong>Mitigations<\/strong><\/h2>\n<p>Users and administrators should update Chrome immediately to mitigate exposure. To manually trigger an update:<\/p>\n<ul class=\"wp-block-list\">\n<li>Open Chrome and navigate to Menu \u2192 Help \u2192 About Google Chrome<\/li>\n<li>Chrome will automatically check for and apply the latest update<\/li>\n<li>Restart the browser to complete the installation<\/li>\n<\/ul>\n<p>Organizations managing Chrome deployments through enterprise policies should prioritize pushing version 146.0.7680.75\/76 across their environment without delay.<\/p>\n<p>Given the active exploitation status of both flaws, waiting for the automatic rollout is not advisable for high-risk environments.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/chrome-zero-day-vulnerabilities-actively-exploited\/\">Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/chrome-zero-day-vulnerabilities-actively-exploited\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code Google has released an urgent security update for its Chrome browser after confirming that two high-severity zero-day vulnerabilities are being actively exploited in the wild. The stable channel has been updated to version 146.0.7680.75\/76 for Windows and macOS, and 146.0.7680.75 for Linux, with [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-11323","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11323"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11323"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11323\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}