bug-bounty497
google347
xss301
microsoft290
facebook261
rce211
exploit198
malware168
apple161
cve135
account-takeover115
bragging-post102
privilege-escalation96
csrf90
phishing86
browser75
writeup74
authentication-bypass69
supply-chain67
dos66
stored-xss65
reflected-xss57
ssrf56
reverse-engineering54
access-control52
react52
input-validation49
cross-site-scripting48
cloudflare47
aws47
docker46
web-security46
lfi46
smart-contract45
sql-injection45
web-application44
ethereum44
ctf43
web343
defi43
oauth43
node41
race-condition39
pentest39
open-source39
idor37
cloud37
info-disclosure36
burp-suite36
auth-bypass35
0
3/10
Google patched two actively exploited Chrome zero-days: CVE-2026-3909 (out-of-bounds write in Skia graphics library enabling code execution) and CVE-2026-3910 (V8 JavaScript engine vulnerability). Both were discovered by Google and fixed within days, with limited technical details withheld until majority of users are patched.
zero-day
chrome
cve-2026-3909
cve-2026-3910
out-of-bounds-write
code-execution
skia
v8
javascript-engine
webassembly
browser-vulnerability
google-security-update
CVE-2026-3909
CVE-2026-3910
CVE-2026-2441
Google
Chrome
Skia
V8
Google Threat Analysis Group
BleepingComputer
Sergiu Gatlan