Google fixes two new Chrome zero-days exploited in attacks
ID: 40490668-0f67-53ff-879f-c24f8c7329c1
STIX ID: report--40490668-0f67-53ff-879f-c24f8c7329c1
Feed Name: Bleeping Computer
Threat Score
Google released emergency patches for two high-severity Chrome zero-days—CVE-2026-3909 (an out-of-bounds write in Skia) and CVE-2026-3910 (an inappropriate implementation issue in V8)—that are being exploited in the wild; updated Stable Desktop versions for Windows (146.0.7680.75), macOS (146.0.7680.76), and Linux (146.0.7680.75) were rolled out, and Google limited disclosure of exploit details until a majority of users are patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
