CVE-2026-3919Use After Free in Google Chrome

CWE-416Use After Free9 documents9 sources
Severity
8.8HIGHNVD
EPSS
0.0%
top 90.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11
Latest updateMar 24

Description

Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome146.0.7680.71146.0.7680.71
NVDgoogle/chrome< 146.0.7680.71
Debianchromium/chromium< 146.0.7680.71-1~deb12u1+2

🔴Vulnerability Details

3
GHSA
GHSA-mqf6-pg39-x737: Use after free in Extensions in Google Chrome prior to 1462026-03-12
OSV
CVE-2026-3919: Use after free in Extensions in Google Chrome prior to 1462026-03-11
CVEList
CVE-2026-3919: Use after free in Extensions in Google Chrome prior to 1462026-03-11

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-39192026-03-24
Red Hat
chromium-browser: Use after free in Extensions2026-03-10
Microsoft
Chromium: CVE-2026-3919 Use after free in Extensions2026-03-10
Debian
CVE-2026-3919: chromium - Use after free in Extensions in Google Chrome prior to 146.0.7680.71 allowed an ...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-3919 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-3919 — Use After Free in Google Chrome | cvebase