Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读文章,理解其主要内容。 文章主要讲的是Google发布了Chrome浏览器的安全更新,修复了两个高危漏洞。这两个漏洞已经被利用了,分别是CVE-2026-3909和CVE-2026-3910,评分都是8.8分。漏洞分别影响Skia图形库和V8引擎,可能导致内存访问或代码执行。Google在3月10日发现并报告了这些漏洞,并且没有透露更多关于攻击者的信息。用户被建议更新到特定版本的Chrome,并且其他基于Chromium的浏览器也需要修复。 接下来,我需要将这些信息浓缩到100字以内。要确保包含关键点:Google发布更新、两个高危漏洞、评分、影响范围、发现日期、建议更新版本以及影响其他浏览器。 可能会遗漏一些细节,比如评分和影响范围的具体描述,但必须保持内容准确且简洁。同时,开头不需要使用“这篇文章”这样的词汇,直接描述内容即可。 最后,检查字数是否符合要求,并确保语言流畅自然。 </think> Google发布Chrome安全更新修复两个高危漏洞(CVE-2026-3909和CVE-2026-3910),评分均为8.8分。漏洞涉及Skia图形库和V8引擎,可能导致内存访问或代码执行。用户应更新至指定版本以获得保护。 2026-3-13 09:17:0 Author: thehackernews.com(查看原文) 阅读量:6 收藏

Browser Security / Vulnerability

Google on Thursday released security updates for its Chrome web browser to address two high-severity vulnerabilities that it said have been exploited in the wild.

The list of vulnerabilities is as follows -

  • CVE-2026-3909 (CVSS score: 8.8) - An out-of-bounds write vulnerability in the Skia 2D graphics library that allows a remote attacker to perform out-of-bounds memory access via a crafted HTML page.
  • CVE-2026-3910 (CVSS score: 8.8) - An inappropriate implementation vulnerability in the V8 JavaScript and WebAssembly engine that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

Both vulnerabilities were discovered and reported by Google itself on March 10, 2026. As is customary in these cases, no details are available about how the issues are being abused in the wild and who is behind the efforts. This is done so as to prevent other threat actors from exploiting the issues.

"Google is aware that exploits for both CVE-2026-3909 and CVE-2026-3910 exist in the wild," the company noted.

The development comes less than a month after Google shipped fixes for a high-severity use-after-free bug in Chrome's CSS component (CVE-2026-2441, CVSS score: 8.8) that had also been exploited as a zero-day. Google has patched a total of three actively weaponized Chrome zero-days since the start of the year.

For optimal protection, users are advised to update their Chrome browser to versions 146.0.7680.75/76 for Windows and Apple macOS, and 146.0.7680.75 for Linux. To make sure the latest updates are installed, users can navigate to More > Help > About Google Chrome and select Relaunch.

Users of other Chromium-based browsers, such as Microsoft Edge, Brave, Opera, and Vivaldi, are also advised to apply the fixes as and when they become available.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/03/google-fixes-two-chrome-zero-days.html
如有侵权请联系:admin#unsafe.sh