Google has announced the release of emergency security updates for its popular Chrome browser , addressing two serious security flaws. According to the company, these are zero-days, vulnerabilities that have already been actively exploited by attackers. The discovery of these vulnerabilities raises new concerns about the security of modern browsers as millions of users rely on them every day to work, communicate and access critical online services.

Chrome: Two high severity vulnerabilities
According to the information released by Google, the problems are listed as CVE-2026-3909 and CVE-2026-3910 with a CVSS score of 8.8 , which places them in the high-risk category for users.
The first vulnerability is related to the Skia 2D and concerns an out-of-bounds write. A remote attacker could exploit this vulnerability via a specially crafted HTML to gain access to memory areas that should not normally be accessible.
See also: SQLi vulnerability in Ally plugin affects 250k+ WordPress sites
The second issue is located in JavaScript and WebAssembly engine , where an implementation error could allow an attacker to execute arbitrary code within the browser's sandbox (also using a maliciously crafted HTML page).
What does zero-day mean for user security?
While Google did not reveal technical details about how the vulnerabilities were exploited, it confirmed that there are already active exploits that exploit them. The practice of withholding information is considered common in the cybersecurity industry to prevent further spread of attacks before patches are widely deployed.

Zero-days are considered particularly dangerous because they exploit software vulnerabilities before most users have time to install updates. This makes them a valuable tool for cybercrime groups and advanced state-sponsored digital espionage operations .
See also: Critical vulnerabilities in n8n allow remote code execution
Continued pressure on Chrome security
The new warning comes less than a month after another serious security flaw in Chrome's CSS component was discovered. It was classified as CVE-2026-2441 and was also exploited as a zero-day attack.
Since the beginning of 2026, Google has fixed three different zero-day bugs in its browser, which shows how attractive a target browsers remain for attackers.
As modern applications increasingly move to the cloud, the browser is essentially becoming a primary work platform. This means that any vulnerability can act as a potential gateway to corporate data, accounts, and personal information.
Updates that users should install
For increased protection, Google urges users to immediately upgrade Chrome to versions 146.0.7680.75/76 for Windows and macOS , and to version 146.0.7680.75 for Linux.
The process is simple and is done through the More by selecting Help and then About Google Chrome where the user can restart the program after installing the update.
See also: Vulnerability in MediaTek chips affects Android smartphones

Impact on the entire Chromium ecosystem
The fixes not only concern Chrome but also all browsers based on the Chromium such as Microsoft Edge, Brave, Opera and Vivaldi which are expected to integrate the same security patches soon.
The case highlights once again the importance of regular software updates and users' digital vigilance . In an environment where cyberattacks are constantly evolving, delayed upgrades can turn into a serious security risk. At the same time, experts remind that the use of modern protection mechanisms, such as sandboxing, process isolation and continuous threat monitoring, helps limit the impact even when unknown vulnerabilities appear. Therefore, timely installation of updates remains one of the most effective defense measures against modern digital threats that target both ordinary users and large organizations that rely on the Internet daily for critical functions and services. In addition, the case reminds us of how critical the cooperation between companies and researchers is .
