Netfox
HomeQ&AAnti-ScamNotifications
© 2026 Netfox. All rights reserved.
Terms of ServicePrivacy PolicyAbout UsEditorial Policy
Comment
Technology

Chrome Security Update: 29 Flaws Fixed in Version 146

Galvin Prescott
Galvin Prescott
Mar 13, 20264 min
0
0
0
205
Google releases Chrome 146 to patch 29 vulnerabilities, including a critical WebML flaw and active zero-days. Update now to block remote code execution risks.

Chrome 146 Deployments Target Critical WebML and V8 Risks

Google has officially promoted Chrome 146 to the stable channel for Windows, Mac, and Linux, delivering a massive security overhaul that addresses 29 documented vulnerabilities. The release, specifically version 146.0.7680.71/72, was accelerated following the discovery of high-risk memory corruption issues that could allow remote attackers to bypass browser sandboxes.

Among the 29 patches, the most severe is CVE-2026-3913, a critical-severity heap buffer overflow located in the WebML (Web Machine Learning) component. Discovered by researcher Tobias Wienand, the flaw carries a $33,000 bounty and allows for total system compromise if a user simply visits a maliciously crafted webpage. This update marks a significant point in the Cybersecurity Sector, as it highlights the increasing attack surface of browser-based AI and machine learning APIs.

Rapid Escalation: Zero-Day Exploits Found in the Wild

Within 48 hours of the initial version 146 release, Google shifted to an emergency footing, issuing an out-of-band update (146.0.7680.75/76) to address two high-severity zero-day vulnerabilities. Tracked as CVE-2026-3909 and CVE-2026-3910, these flaws affect the Skia graphics library and the V8 JavaScript engine, respectively.

Unlike theoretical risks, Google confirmed that exploits for these specific bugs are currently being used in active attacks. The Skia vulnerability involves an out-of-bounds write that can corrupt system memory, while the V8 flaw allows for arbitrary code execution within the browser's rendering process. These "in-the-wild" exploitations force a mandatory update cycle for enterprise IT departments and general users alike to prevent unauthorized data exfiltration.

The "Memory Safety" Crisis in Modern Browsers

While the industry often focuses on feature parity, the current Chrome update cycle reveals a deeper structural crisis: the persistence of C++ memory safety issues. Despite Google’s aggressive push toward "Memory Safe" languages like Rust for new components, over 70% of the high-severity vulnerabilities in this 29-patch batch—including those in WebML and MediaStream—stem from classic "Use-After-Free" (UAF) and buffer overflow errors.

What competitors and standard reporting often overlook is the "Security Regression" risk inherent in the WebML API. As browsers integrate more direct hardware-acceleration features to support local AI models, they inadvertently open low-level memory gates that were previously shielded. This version 146 update is not just a routine patch; it is a defensive recalibration against a new class of "Hardware-Adjacent" browser exploits that target the bridge between the web renderer and the GPU.

Systemic Impact on the Chromium Ecosystem

Because Chrome serves as the foundation for the Chromium open-source project, this security wave creates a massive downstream ripple effect. Competitors including Microsoft Edge, Brave, and Opera are now forced into synchronized emergency deployments to patch the same 29 vulnerabilities.

For the Software Development Sector, the $210,000 in total bug bounties paid out for this release underscores the rising "cost of security" in the browser wars. As Google prepares to move to a permanent two-week release cycle starting in September 2026, the window for attackers to exploit unpatched "N-day" vulnerabilities is shrinking, but the pressure on users to maintain a constant state of "update-readiness" is reaching an all-time high.

March 2026 Chrome Security Patch Breakdown

CVE IDSeverityComponent AffectedVulnerability Type
CVE-2026-3913CriticalWebMLHeap Buffer Overflow
CVE-2026-3909HighSkia (Graphics)Zero-Day (Out-of-bounds Write)
CVE-2026-3910HighV8 (JavaScript)Zero-Day (Inappropriate Implementation)
CVE-2026-3921HighTextEncodingUse-after-free
CVE-2026-3924HighWindowDialogUse-after-free

The persistent targeting of core components like Skia and V8 indicates that threat actors are moving away from simple phishing toward sophisticated, zero-click browser exploitation. As autonomous agents and web-based AI tools become standard, the "browser" is no longer just a window to the internet—it has become the primary execution environment for the operating system, making it the most lucrative and volatile target in the global threat landscape.

Comments (0)

Sort by

Please login to comment

Sign in to share your thoughts and connect with the community

Loading...

Related news

Learn about the cybersecurity measures and digital lockdown procedures implemented for US officials traveling to China for diplomatic missions.

How US Officials Manage Digital Security During China Visits

135 views•3 min
Federal prosecutors indicted Manuel G. Garcia for allegedly posting graphic death threats targeting South Dakota Gov. Kristi Noem and former AG Pam Bondi.

Man Indicted for Death Threats Against Noem and Bondi

153 views•2 min
FBI Director Kash Patel alleges a four-day delay in federal involvement in the Nancy Guthrie case. Sheriff Chris Nanos refutes claims of sidelined cooperation.

Kash Patel and Sheriff Nanos Clash Over Nancy Guthrie Case

142 views•4 min
Xiaomi's MiMo V2.5 Pro tops the GDPval-AA agentic benchmark with a score of 1578, outperforming Kimi K2.6 and DeepSeek V4 Pro in real-world work tasks.

Xiaomi MiMo V2.5 Pro Leads GDPval-AA Agentic Benchmarks

243 views•5 min
London's Metropolitan Police are investigating the stabbing of two Jewish men in Golders Green as an act of terrorism following a spate of arson attacks.

London Golders Green Stabbing Declared Act of Terrorism

145 views•2 min
Google celebrates 20 years of Translate with a new interactive AI pronunciation tool and launches an experimental "Ask YouTube" conversational search feature.

Google Translate Adds AI Pronunciation Practice Tool

636 views•4 min
Turtle Beach's new Command Series peripherals feature customizable touchscreens for macro management and system monitoring. Discover the technical specs and release details.

Turtle Beach Command Series Touchscreen Peripheral Specs

132 views•3 min
Apple announces John Ternus will become CEO on September 1, 2026, while Tim Cook moves to Executive Chairman. An analysis of Apple's hardware-led future.

John Ternus Named Apple CEO as Tim Cook Shifts to Chairman

215 views•4 min
Anthropic Labs debuts Claude Design, a tool using Claude Opus 4.7 to generate interactive prototypes and design systems directly from existing codebases.

Anthropic Claude Design: Prototyping and Code Handoff Analysis

227 views•4 min
IEA Director Fatih Birol warns Europe has six weeks of jet fuel left as the Iran war blockades the Strait of Hormuz, threatening a two-year recovery period.

Europe Jet Fuel Shortage: IEA Warns of 6-Week Supply Limit

247 views•4 min
The DJI Osmo Pocket 4 introduces 4K/240p slow-motion and improved dynamic range. Here is how the hardware changes impact real-world vlogging and production.

DJI Osmo Pocket 4 Specs: 4K/240p and Improved Dynamic Range

183 views•3 min
Porsche reveals the 2027 911 GT3 S/C, combining the 510 PS naturally aspirated engine with a magnesium-ribbed automatic roof and 6-speed manual transmission.

2027 Porsche 911 GT3 S/C: Specs, Weight, and Analysis

222 views•5 min
Leaks suggest Apple will introduce a Deep Red finish for the iPhone 18 Pro, while Android manufacturers reportedly prepare similar shades for 2026.

iPhone 18 Pro Deep Red Color Leak and Android Response

153 views•3 min
US Treasury Secretary Scott Bessent convenes bank CEOs as Anthropic's Claude Mythos model demonstrates autonomous discovery of critical zero-day vulnerabilities.

Anthropic Mythos Prompts Treasury Meeting with Bank CEOs

329 views•5 min
GitButler, co-founded by GitHub’s Scott Chacon, raises $17M Series A to move software development beyond 20-year-old Git workflows and support AI collaboration.

GitButler Raises $17M to Redesign Version Control for AI

284 views•3 min
As Apple's M5 and Intel's Panther Lake arrive in 2026, the CPU is no longer the center of the chip. Discover how NPUs and specialized accelerators are taking over.

CPU vs NPU: The Shift to Specialized Silicon in 2026

244 views•4 min
With US fertility hitting a record low in 2025, researchers explore the economic benefits of smaller families against the long-term risks of a shrinking workforce.

Global fertility falls as US birth rates hit record low

297 views•4 min
Leaked specs for the MediaTek Dimensity 9600 reveal a 5GHz clock speed target, Arm Magni GPU, and TSMC N2p process for 2027 flagship smartphones.

MediaTek Dimensity 9600 Leaks: 5GHz and N2p Architecture

231 views•3 min
Jurors in the capital murder trial of former FedEx driver Tanner Horner viewed video of his confession regarding the 2022 death of 7-year-old Athena Strand.

Tanner Horner Trial: FedEx Driver Confession Video Shown

133 views•3 min
Storm Dave has cleared the UK after causing widespread power outages, bridge closures, and rail delays. Met Office reports winds up to 93mph and Easter snow.

Storm Dave Impacts: Power Outages and Travel Disruption

158 views•3 min