Chrome Zero-Days in Skia and V8: 3.5B Users Affected
CVE-2026-3909 and CVE-2026-3910 -- Actively Exploited, Patched in Chrome 146
Two actively exploited zero-days hit Chrome: CVE-2026-3909 (Skia memory corruption) and CVE-2026-3910 (V8 type confusion). A single malicious page could trigger arbitrary code execution on Windows, macOS, and Linux. Both are patched in Chrome 146.