Vulnerabilità ed exploit

Vulnerabilità Chromium Sfruttate Attivamente; Debian Rilascia Aggiornamenti

Debian ha pubblicato aggiornamenti di sicurezza per Chromium che risolvono CVE-2026-3909 e CVE-2026-3910. Google segnala exploit in the wild; le falle possono consentire arbitrary code execution, denial of service o information disclosure.

1 fonte · 18 mar

CVE-2026-3909

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. EPSS 33% (97º percentile). Patch Microsoft: Release Notes.

Data di correzione federale CISA 27 mar

CVE-2026-3910

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. EPSS 23% (96º percentile). Patch Microsoft: Release Notes.

Data di correzione federale CISA 27 mar

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-18

Every edition of this story: Vulnerabilità Chromium Sfruttate Attivamente; Debian Rilascia Aggiornamenti

Altro da oggi