Google Chrome Double Zero-Day — Skia OOB Write & V8 Implementation Flaw (CVE-2026-3909, CVE-2026-3910) — Threadlinqs Intelligence
As of 2026-05-30, Google Chrome Double Zero-Day — Skia OOB Write & V8 Implementation Flaw (CVE-2026-3909, CVE-2026-3910) is a critical-severity zero day threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0230 · Severity: CRITICAL · CVSS: 8.8 · Status: PATCHED · Category: ZERO_DAY
Attribution: N/A · UNKNOWN
Two actively exploited zero-day vulnerabilities in Google Chrome — CVE-2026-3909 (out-of-bounds write in Skia graphics library, CVSS 8.8) and CVE-2026-3910 (inappropriate implementation in V8
On March 12, 2026, Google released an emergency stable channel update for Chrome (146.0.7680.75/76 for Windows/macOS, 146.0.7680.75 for Linux) addressing two high-severity zero-day vulnerabilities that were actively exploited in the wild. Both were discovered internally by Google's Threat Analysis Group (TAG) on March 10, 2026, with patches shipped within two days.
CVE-2026-3909 is an out-of-bounds write vulnerability (CWE-787) in the Skia 2D graphics library, which serves as the core rendering engine for Google Chrome, ChromeOS, Android, and Flutter. The flaw allows a remote attacker to perform out-of-bounds memory access via a specially crafted HTML page. Memory corruption in Skia can lead to arbitrary code execution in the renderer process context. When chained with other bugs, an out-of-bounds write in Skia can potentially enable sandbox escape from the renderer process. Skia processes all visual content rendered in the browser — fonts, vector graphics, images, and UI elements — making it a high-value target for attackers.
CVE-2026-3910 is an inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine. Classified under CWE-94 (Code Injection) and CWE-119 (Improper Restriction of Operations within Memory Buffer Bounds), this flaw enables a remote attacker to execute arbitrary code inside the V8 sandbox via a crafted HTML page. V8 vulnerabilities are particularly dangerous because they can be triggered simply by directing victims to malicious or compromised websites — no file download or user interaction beyond navigation is required. Two public proof-of-concept exploits have been reported on GitHub (Chromium issue 491410818).
Both vulnerabilities share an identical CVSS 3.1 score of 8.8 (High) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H — indicating network-accessible, low-complexity attacks requiring only user interaction (visiting a malicious page) with high impact to confidentiality, integrity, and availability.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on March 13, 2026, establishing a federal remediation deadline of March 27, 2026 under Binding Operational Directive 22-01. This marks the third actively exploited Chrome zero-day of 2026, following CVE-2026-2441 (use-after-free in CSS handling) patched in February.
The attack surface extends beyond Chrome to all Chromium-based browsers including Microsoft Edge, Brave, Opera, and Vivaldi. Exploitation delivery vectors observed in similar browser zero-day campaigns include spear-phishing links, watering hole compromises of legitimate websites, malvertising through ad networks, and compromised developer tooling or forums. Google has deliberately withheld exploitation details and threat actor attribution to prevent additional weaponization while users update.
The combined impact of these two vulnerabilities is severe: CVE-2026-3909 provides memory corruption capability in the graphics pipeline, while CVE-2026-3910 enables code execution in the JavaScript engine. If chained together, an attacker could potentially achieve full renderer compromise and, combined with a sandbox escape, gain arbitrary code execution on the host system.
Weaknesses (CWE)
CWE-787, CWE-94, CWE-119
Target sectors: government, technology, financial, defense, healthcare, energy, telecommunications, education, media
Target regions: Global, North America, Europe, Asia-Pacific
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ZERO_DAY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-3909, CVE-2026-3910, T1189, T1566, T1203, T1059, T1204, T1176, T1068, T1055, T1027, T1497