216.73.217.22

CVE-2026-3909

· Published 13/03/2026 01:00 · Modified 14/04/2026 11:20 · Author: The MITRE Corporation

Labels: CVE-2026-3909 2026-03-13CVE-2026-3909CWE-787[email protected]

Essential information

Published
13/03/2026 01:00
Modified
14/04/2026 11:20
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
8.8 HIGH (v3.1)
CISA KEV
Yes
CWE
EPSS (First)
P20.7% ?EPSS percentile: rank of this vulnerability versus all others. Higher percentile = more likely to be exploited. Learn more (score 0.00068)
CVSS vector
CVSS:3.1/AV:N/C:H/I:H/A:H

CVSS metrics

Description

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
google / chrome cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
apple / macos cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
linux / linux kernel cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
microsoft / windows cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

References