Skip to content
Vulnerability intelligence

CVE-2026-3910

CVSS 8.8. Out-of-bounds read/write in V8's JavaScript and WebAssembly engine. Arbitrary code execution via a crafted HTML page. All Chromium-based browsers affected — Chrome, Edge, Brave, Opera. Google confirmed active exploitation before the patch. The web's runtime engine has been actively compromised five times this year.

2026