Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Google Rolls Out Emergency Chrome Update to Patch Zero-Days

Google Rolls Out Emergency Chrome Update to Patch Zero-Days

Posted on March 13, 2026 By CWS

In a swift response to emerging threats, Google has released an urgent update for Chrome, version 146, to address two critical zero-day vulnerabilities. These flaws, identified as CVE-2026-3909 and CVE-2026-3910, were actively exploited and demanded immediate attention.

Details of the Security Flaws

The vulnerabilities, both carrying a CVSS score of 8.8, were detected by Google on March 10. CVE-2026-3909 is attributed to an out-of-bounds write issue within the Skia graphics library. This defect allows malicious HTML pages to corrupt memory, potentially leading to unauthorized code execution or system crashes.

On the other hand, CVE-2026-3910 involves an improper implementation flaw in the V8 JavaScript engine. This weakness can be exploited to create malicious HTML pages, enabling arbitrary code execution. Such vulnerabilities are often leveraged in sandbox escape attacks, posing significant security risks.

Patch Deployment and Impact

Google has not disclosed the specifics of the attacks exploiting these vulnerabilities so far. However, the security patches are now available in Chrome versions 146.0.7680.75/76 for Windows and macOS, and version 146.0.7680.75 for Linux. Additionally, the fixes have been included in Chrome for Android version 146.0.76380.115.

This emergency update was deployed merely two days after Chrome 146 reached the stable channel, which included resolutions for 29 different security flaws. These ranged from a critical bug in WebML to various high-severity issues across components such as Web Speech and Extensions.

Incentives for Security Researchers

In recognition of contributions to its security efforts, Google has awarded approximately $210,000 in bounty rewards to researchers who identified these vulnerabilities. The company noted that the actual total could be higher, as payouts for 10 vulnerabilities were not disclosed.

Notably, security expert Tobias Wienand was awarded $76,000 for discovering two issues in WebML. Additional rewards of $43,000 and $36,000 were given to researchers who found high-severity flaws in WebML and Web Speech, respectively.

As Google continues to enhance browser security, users are advised to promptly update to the latest version of Chrome to safeguard against potential threats.

Security Week News Tags:browser security, Chrome, CVE-2026-3909, CVE-2026-3910, emergency update, Google, security update, Skia, V8 JavaScript engine, zero-day vulnerabilities

Post navigation

Previous Post: Global Crackdown Dismantles SocksEscort Proxy Botnet Network
Next Post: Google Urgently Updates Chrome to Fix Exploited Flaws

Related Posts

All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher All Microsoft Entra Tenants Were Exposed to Silent Compromise via Invisible Actor Tokens: Researcher Security Week News
Pixnapping Attack Steals Data From Google, Samsung Android Phones Pixnapping Attack Steals Data From Google, Samsung Android Phones Security Week News
Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack Over 6,700 Private Repositories Made Public in Nx Supply Chain Attack Security Week News
AI Is Supercharging Phishing: Here’s How to Fight Back AI Is Supercharging Phishing: Here’s How to Fight Back Security Week News
40,000 Security Cameras Exposed to Remote Hacking 40,000 Security Cameras Exposed to Remote Hacking Security Week News
Luxury Brands Fined  Million in South Korea for Data Breaches Luxury Brands Fined $25 Million in South Korea for Data Breaches Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Misuse in Yemen: Houthis Attempt Advanced Weapon Development
  • Critical Flaw in CSF on cPanel Allows Remote Command Execution
  • Ubuntu 24.04.5 LTS Launches with Linux 7.0 Kernel
  • Android Malware Combines Ransomware with Espionage
  • Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark