Skip to content
COOEY

EXPOSURES › CVE-2026-3909

CVE-2026-3909

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-03-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-3909 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildransomwareunpatched

Google Skia contains an actively exploited out-of-bounds write vulnerability enabling remote memory access via crafted HTML.

This vulnerability allows remote attackers to perform out-of-bounds memory access through crafted HTML pages, affecting Google Chrome, ChromeOS, Android, and Flutter. DIB organizations must patch immediately as the CVE is actively exploited and linked to ransomware campaigns, creating significant exposure for any system running these products.

Shame score — While actively exploited, the vulnerability is a known CVE with no FCA settlement or vendor negligence, resulting in moderate embarrassment.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized