Exploited Vulnerabilities Daily
🌐 English

Home › Google

CVE-2026-3909: Google Skia

EPSS2.3%No. 1567 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV75
Same product1
FieldValue
VendorGoogle
ProductSkia
NameGoogle Skia Out-of-Bounds Write Vulnerability
Added to KEV2026-03-13
US federal due date2026-03-27
Ransomware useUnknown
CWECWE-787

CISA description

Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

NVD — CVE-2026-3909

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Google Skia vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-13.