Skip to content
COOEY

EXPOSURES › CVE-2026-3910

CVE-2026-3910

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-03-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-3910 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildransomwaresupply-chaindata-breachunpatched

Google Chromium V8 allows remote code execution via crafted HTML pages, enabling attackers to bypass sandbox protections.

This vulnerability permits arbitrary code execution within the browser sandbox through a crafted HTML page, posing a severe risk to DIB organizations relying on Chromium-based browsers for web-based tools or portals. Immediate patching is critical to prevent remote attackers from exploiting this flaw to compromise user sessions or escalate privileges.

Shame score — Google shipped a high-severity RCE vulnerability in a widely deployed browser engine that was actively exploited in the wild, indicating a failure in timely detection and patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized