Historical catalog analysis: CISA added this entry on March 13, 2026. The entry reflects catalog information retrieved on August 31, 2026, not a snapshot archived on the inclusion date. Check current vendor guidance before acting.
What the vulnerability is
CVE-2026-3909 is an out-of-bounds write vulnerability (CWE-787) located within the Google Skia graphics library. This flaw allows a remote attacker to perform out-of-bounds memory access. The reported attack vector involves the delivery of a specially crafted HTML page to a target system.
Exposure and applicability
Because Skia is a widely utilized open-source graphics library, exposure extends beyond a single application. Affected products explicitly identified include:
* Google Chrome
* ChromeOS
* Android
* Flutter
Other third-party products that integrate the Skia library may also be susceptible. Organizations must identify all assets running these platforms or utilizing Skia as a dependency to determine their total exposure surface.
Remediation priorities
Our analysis suggests prioritizing remediation based on the asset’s exposure to untrusted web content, as the attack vector is remote via HTML.
- Immediate Patching: Prioritize updates for browser-based assets (Chrome and ChromeOS) and mobile endpoints (Android), as these are primary vectors for crafted HTML delivery.
- Dependency Audit: For developers using Flutter or integrating Skia into proprietary software, verify the version of the library in use and update to a patched release provided by Google or the respective vendor.
- Vendor Verification: Since this is a common component, security teams should consult specific product vendors for patching status if they utilize non-Google products that may embed Skia.
How to validate remediation
Verification must move beyond simple version checks, as a deployed update does not always guarantee the vulnerability is mitigated in the active runtime environment.
- Build Verification: Confirm that the deployed binary or system image corresponds to the patched version specified by the vendor.
- Configuration Audit: Ensure that automatic update mechanisms are functioning and that no legacy, unpatched versions of the library remain on the filesystem (shadow IT or orphaned dependencies).
- Deployment Confirmation: Use asset management tools to verify that the patch has been successfully applied across all targeted endpoints, rather than relying on a subset of successful updates.
Limits and open questions
There is currently uncertainty regarding whether this vulnerability has been leveraged in ransomware campaigns. Furthermore, because Skia is embedded in various third-party applications, the full list of affected software remains unknown.
Residual risk persists if an organization cannot identify every instance where the Skia library is embedded within proprietary or third-party binaries. Patching the primary OS or browser may not resolve exposure in standalone applications that bundle their own version of the library.
Source and editorial note
CVE-2026-3909: Google Skia Out-of-Bounds Write Vulnerability · Source date: March 13, 2026 · Retrieved August 31, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Archive date: March 16, 2026. The displayed post date is assigned three days after the source date to organize this retrospective archive; it does not mean this site published the analysis then. First published by this site: September 18, 2026 at 00:32 UTC.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗