1 min read
Multiple Vulnerabilities Found in ConnectWise ScreenConnect
Published 02/27/2024 I. Targeted Entities ConnectWise ScreenConnect customers
4 min read
Cyber Florida SOCAP Team
:
Updated on September 16, 2026
Originally Published April 1, 2026
On 13th March, Google pushed out an emergency security patch to address a pair of critical zero-day vulnerabilities used by attackers to actively exploit the Google Chrome web browser. CVE-2026-3909 and CVE-2026-3910 both carry a high severity CVSS score of 8.8 (a standardized way to measure vulnerabilities’ severity). Both have been confirmed and recognized by Google and the Cybersecurity and Infrastructure Security Agency (CISA).
Due to the nature of these flaws existing within the foundation of the Chromium code base, which caused these vulnerabilities to be exploited, the attack surface extends beyond Google Chrome. Any browser or application utilizing the Chromium engine is affected, common examples include:
The vulnerabilities target two distinct core components:
Since these attacks only require a simple click from a victim or visiting a malicious webpage, the risk is immediate; users are urged to update their browsers to mitigate any potential threats.
Both of these zero-day vulnerabilities target the renderer process, a sandboxed environment responsible for parsing HTML, executing JavaScript, and drawing visual elements on the screen. Since the renderer handles a lot of untrusted data on the web, it is a primary and common target for browser exploitation.
To understand the severity of CVE-2026-3909 and CVE-2026-3910, it is important to look at how the foundational architecture of the Chromium engine manages untrusted web content.
CVE-2026-3909:
Skia Out-of-Bounds (OOB) Write: Skia is a foundational open source 2D graphics library used by Chromium. It renders all visual elements on a webpage: SVG (Scalable Vector Graphics) paths, HTML elements, CSS borders, and web fonts.
CVE-2026-3910
V8 Inappropriate Implementation: V8 is Google’s JavaScript and WebAssembly engine. V8 has a multi-tiered architecture, which relies on an interpreter and “Just-In-Time” optimizing compiler.
Since CVE-2026-3909 and CVE-2026-3910 are being actively exploited in the wild and require no user interaction beyond visiting a malicious webpage, organizations must prioritize immediate remediation.
The only definitive method to eliminate the risk posed by these vulnerabilities is to update the affected software. Security and IT operations teams should utilize automated patch management systems to push these updates across their respective networks.
Windows and macOS: Version 146.0.7680.75 or 146.0.7680.76
Linux: Version 146.0.7680.75
Security Operations Centers (SOC) should continue to ensure their Endpoint Detection and Response (EDR) platforms are configured to monitor for anomalous behavior originating from browser processes. Specifically, analysts should hunt for:
https://nvd.nist.gov/vuln/detail/CVE-2026-3910
https://nvd.nist.gov/vuln/detail/CVE-2026-3909
https://chromereleases.googleblog.com/2026/03/stable-channel-update-for-desktop_12.html
https://www.sentinelone.com/vulnerability-database/cve-2026-3910/
https://www.chromium.org/Home/chromium-security/
Threat Advisory created by The Cyber Florida Security Operations Center. Contributing Security Analysts: Taylor Alvarez
1 min read
Published 02/27/2024 I. Targeted Entities ConnectWise ScreenConnect customers
1 min read
Originally published: 06/16/2022 I. Targeted Entities Microsoft Office users II. Introduction Microsoft has recently established a workaround for a...
1 min read
Originally published 07/14/2022