Google fixes two new Chrome zero-days exploited in attacks
Two high-severity Chrome vulnerabilities that were used in zero-day attacks have been patched by Google's emergency security patches.
In a security advisory released on Thursday, Google stated that it is aware that exploits for CVE-2026-3909 and CVE-2026-3910 exist in the wild.
An out-of-bounds write vulnerability in Skia, an open-source 2D graphics library that renders web content and UI elements, is the source of the first zero-day (CVE-2026-3909). Attackers can utilize this vulnerability to crash the web browser or possibly obtain code execution.
An improper implementation vulnerability in the V8 JavaScript and WebAssembly engine is the second one (CVE-2026-3910).
Within two days of users in the Stable Desktop channel reporting both security vulnerabilities, Google fixed th...

