Skip to main content

Skia vulnerabilities

1 published alerts for Google Skia.

Actively exploited (KEV)

CVE-2026-3909

Google Skia Out-of-Bounds Write Vulnerability

Google Skia is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-3909). Google Skia contains an out-of-bounds write vulnerability that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products. CISA remediation due date: 2026-03-27. If you need help checking exposure, call (864) 335-9223.