CVE-2026-3909: Google Skia
EPSS2.3%No. 1567 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV75
Same product1
| Field | Value |
|---|---|
| Vendor | |
| Product | Skia |
| Name | Google Skia Out-of-Bounds Write Vulnerability |
| Added to KEV | 2026-03-13 |
| US federal due date | 2026-03-27 |
| Ransomware use | Unknown |
| CWE | CWE-787 |
CISA description
Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Google Skia vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-13.