Google Patches Two Chrome Zero-Days Exploited in the Wild
Google released an emergency Chrome update (v146.0.7680.75+) fixing two actively exploited zero-days: CVE-2026-3909, an out-of-bounds write in the Skia graphics library, and CVE-2026-3910, an inappropriate implementation in the V8 JavaScript engine enabling arbitrary code execution. Both were triggered via crafted HTML pages with confirmed in-the-wild exploits.