Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Rolls Out Emergency Chrome Update to Patch Zero-Days

Google Rolls Out Emergency Chrome Update to Patch Zero-Days

Posted on March 13, 2026 By CWS

In a swift response to emerging threats, Google has released an urgent update for Chrome, version 146, to address two critical zero-day vulnerabilities. These flaws, identified as CVE-2026-3909 and CVE-2026-3910, were actively exploited and demanded immediate attention.

Details of the Security Flaws

The vulnerabilities, both carrying a CVSS score of 8.8, were detected by Google on March 10. CVE-2026-3909 is attributed to an out-of-bounds write issue within the Skia graphics library. This defect allows malicious HTML pages to corrupt memory, potentially leading to unauthorized code execution or system crashes.

On the other hand, CVE-2026-3910 involves an improper implementation flaw in the V8 JavaScript engine. This weakness can be exploited to create malicious HTML pages, enabling arbitrary code execution. Such vulnerabilities are often leveraged in sandbox escape attacks, posing significant security risks.

Patch Deployment and Impact

Google has not disclosed the specifics of the attacks exploiting these vulnerabilities so far. However, the security patches are now available in Chrome versions 146.0.7680.75/76 for Windows and macOS, and version 146.0.7680.75 for Linux. Additionally, the fixes have been included in Chrome for Android version 146.0.76380.115.

This emergency update was deployed merely two days after Chrome 146 reached the stable channel, which included resolutions for 29 different security flaws. These ranged from a critical bug in WebML to various high-severity issues across components such as Web Speech and Extensions.

Incentives for Security Researchers

In recognition of contributions to its security efforts, Google has awarded approximately $210,000 in bounty rewards to researchers who identified these vulnerabilities. The company noted that the actual total could be higher, as payouts for 10 vulnerabilities were not disclosed.

Notably, security expert Tobias Wienand was awarded $76,000 for discovering two issues in WebML. Additional rewards of $43,000 and $36,000 were given to researchers who found high-severity flaws in WebML and Web Speech, respectively.

As Google continues to enhance browser security, users are advised to promptly update to the latest version of Chrome to safeguard against potential threats.

Security Week News Tags:browser security, Chrome, CVE-2026-3909, CVE-2026-3910, emergency update, Google, security update, Skia, V8 JavaScript engine, zero-day vulnerabilities

Post navigation

Previous Post: Global Crackdown Dismantles SocksEscort Proxy Botnet Network
Next Post: Google Urgently Updates Chrome to Fix Exploited Flaws

Related Posts

Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000 Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000 Security Week News
Chinese Threat Actor Uses DKnife Implant for Attacks Chinese Threat Actor Uses DKnife Implant for Attacks Security Week News
Helmet Security Emerges From Stealth Mode With  Million in Funding Helmet Security Emerges From Stealth Mode With $9 Million in Funding Security Week News
India Rolls Back Order to Preinstall Cybersecurity App on Smartphones India Rolls Back Order to Preinstall Cybersecurity App on Smartphones Security Week News
Microsoft Silently Mitigated Exploited LNK Vulnerability Microsoft Silently Mitigated Exploited LNK Vulnerability Security Week News
Global Crackdown on Aisuru and Kimwolf Botnets Global Crackdown on Aisuru and Kimwolf Botnets Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agent Deletes Database in Seconds: Security Alert
  • North Korean Hackers Target Pharma Firms with Malware
  • EU Pushes Google to Share Anonymized User Data
  • Google Patches Critical Gemini CLI Vulnerability
  • ClickUp’s API Key Leak Exposes Fortune 500 Emails

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agent Deletes Database in Seconds: Security Alert
  • North Korean Hackers Target Pharma Firms with Malware
  • EU Pushes Google to Share Anonymized User Data
  • Google Patches Critical Gemini CLI Vulnerability
  • ClickUp’s API Key Leak Exposes Fortune 500 Emails

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark