Vulnerabilities & Exploits

Chromium Flaws Actively Exploited; Debian Issues Updates

Debian released security updates for Chromium fixing two tracked vulnerabilities. Google reports exploits exist in the wild; the flaws can allow code execution, denial of service, or information disclosure. Fixes are in bookworm (146.0.7680.80-1~deb12u1) and trixie (146.0.7680.80-1~deb13u1).

1 source · Mar 18

CVE-2026-3909

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 33% (97th percentile). Microsoft patch: Release Notes.

CISA federal remediation date Mar 27

CVE-2026-3910

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 23% (96th percentile). Microsoft patch: Release Notes.

CISA federal remediation date Mar 27

Timeline

Sources

Part of the PlainSec briefing for 2026-03-17

Every edition of this story: Chromium Flaws Actively Exploited; Debian Issues Updates

More from today