LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-3910: Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 13, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 27, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-3910 to its Known Exploited Vulnerabilities catalog on Mar 13, 2026, with a federal patch deadline of Mar 27, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Google Chromium V8 contains an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a…

This vulnerability in Google Chromium V8 is an improper restriction of operations within the bounds of a memory buffer. It could allow a remote attacker to execute arbitrary code inside the browser sandbox by serving a crafted HTML page to a victim. The issue matters for any environment where users access web content through Chromium-based browsers, as successful exploitation could lead to code running within the sandboxed process.

How it works

The weakness falls under CWE-119, which covers improper restriction of operations within the bounds of a memory buffer. An attacker abuses the flaw by delivering a crafted HTML page that triggers the memory issue, with the goal of achieving arbitrary code execution inside the sandbox.

Am I affected? How to find it in your systems

This affects Google Chromium V8 and therefore multiple web browsers that utilize the Chromium engine. Inventory endpoints for any installed Chromium-based browsers and confirm the exact versions and configurations against the vendor advisory.

How to remediate

Apply the vendor update named in the advisory as the primary step. For memory buffer restriction issues in rendering engines, maintain a consistent browser update process and verify that automatic updates remain enabled on managed systems.

If you can't patch immediately

Until the update can be applied, reduce exposure by segmenting browser-using systems from sensitive internal resources. Consider virtual patching through network controls that inspect web traffic, disabling unnecessary browser features that process untrusted HTML, and increasing monitoring for anomalous process behavior or sandbox violations. Follow applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations cannot be implemented.

If your data may have been exposed

Vulnerabilities that permit code execution can contribute to breaches when actively exploited. Organizations can run a free exposure scan of their email domains to check for presence in known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedGoogle · Chromium V8
WeaknessCWE-119
Added to CISA KEVMar 13, 2026
Federal patch deadlineMar 27, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities