CVE-2026-3909 is an out-of-bounds write flaw in Skia, the graphics library Chrome uses to render web content and parts of its user interface. Memory corruption bugs like this can sometimes be abused by attackers to crash applications or run their own code if successfully exploited.
Google on Tuesday announced the release of Chrome 145 to the stable channel with fixes for 11 vulnerabilities, including three high-severity bugs. First in line is CVE-2026-2313, a high-severity use-after-free issue in CSS that earned the reporting researchers an $8,000 bug bounty reward. The two other high-severity defects, tracked as CVE-2026-2314 and CVE-2026-2315, were found and reported by Google and are described as a heap buffer overflow in Codecs and an inappropriate implementation in WebGPU, respectively.
BrowserCoPilot is designed to make your workflows easier and faster - and completely customized to you, your prompts, and your writing style. One useful example? Integrate the program directly to your inbox, and let it create one-click emails that use your phrasing and tone, and that gather context from your conversations. Or, write directly in the browser to revise or analyze documents using your saved prompts - or upload images and PDFs to interact with directly.