LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 13, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-3909 to its Known Exploited Vulnerabilities catalog on Mar 13, 2026, with a federal patch deadline of Mar 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome…

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out-of-bounds memory access. The flaw is reached when affected software processes a crafted HTML page. This issue affects Google Chrome, ChromeOS, Android, Flutter, and possibly other products that rely on Skia for graphics operations. Organizations that deploy these components should determine exposure promptly because memory corruption flaws of this class can lead to further compromise once triggered.

How it works

The weakness is recorded as CWE-787, an out-of-bounds write. Skia fails to keep write operations within the intended memory region when handling certain malformed input.

Am I affected? How to find it in your systems

Skia is embedded in Google Chrome, ChromeOS, Android, and Flutter-based applications. Inventory all endpoints, browsers, mobile devices, and custom applications that include these components.

How to remediate

Apply the vendor update referenced in the official advisory as the primary action. After patching, verify that the updated Skia library is active in Chrome, ChromeOS, Android, and Flutter deployments.

If you can't patch immediately

Apply mitigations exactly as described in the vendor instructions. Where mitigations are unavailable, discontinue use of the affected product until an update can be installed.

If your data may have been exposed

Actively exploited memory-safety vulnerabilities have preceded data breaches in other incidents. Organizations can run a free exposure scan of their email addresses to check against known breach data sets while completing the inventory and patching steps above.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Skia
WeaknessCWE-787
Added to CISA KEVMar 13, 2026
Federal patch deadlineMar 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities