Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-3909 — Proof-of-concept exploit for CVE-2026-3909, a Chromium Skia out-of-bounds vulnerability, with patches and crash analysis for reliable triggering in real browser environments. | Kitploit
Tools/GitHubGitHub/jaf0rk/cve-2026-3909
Vulnerability AnalysisExploitationWeb Application ExploitationFuzzingBinary Analysis
GitHubjaf0rk/cve-2026-3909

CVE-2026-3909

Proof-of-concept exploit for CVE-2026-3909, a Chromium Skia out-of-bounds vulnerability, with patches and crash analysis for reliable triggering in real browser environments.

View Repository
2175 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-3909 Chromium Browser PoC

This repository contains a proof-of-concept (PoC) for CVE-2026-3909 that can be reliably triggered in the Chromium browser.

Background

The official Skia fix for this vulnerability only included a simplified demonstration test case:

  • Official Demo: AtlasOobTest.cpp

It cannot run in a real Chromium environment. The official demo was intentionally limited and omitted key triggering conditions.
This PoC is built upon the official demo and has been modified to trigger the vulnerability reliably within a real Chromium browser environment.

Patches Included

This PoC consists of modifications to the following files:

1. raster_implementation.cc.patch

Path: /src/gpu/command_buffer/client/raster_implementation.cc

2. SkChromeRemoteGlyphCache.cpp.patch

Path: /src/third_party/skia/src/text/gpu/SkChromeRemoteGlyphCache.cpp

3. Other

In addition to the two existing patch files, you can also add debugging code inside the DrawAtlas::hasID() function. This allows you to analyze and observe why the abort is being triggered.

    bool hasID(const skgpu::PlotLocator& plotLocator) {
        if (!plotLocator.isValid()) {
            return false;
        }

        uint32_t plot = plotLocator.plotIndex();
        uint32_t page = plotLocator.pageIndex();
        // patch code
        printf("[*] POC plot idx: %x fNumPlots: %x\n", plot, fNumPlots);
        // origin code
        uint64_t plotGeneration = fPages[page].fPlotArray[plot]->genID();
        uint64_t locatorGeneration = plotLocator.genID();
        return plot < fNumPlots && page < fNumActivePages && plotGeneration == locatorGeneration;
    }

output:

[*] POC plot idx: 1f fNumPlots: 10

Git log

Chromium:

commit e00a64ead1abef9447943efede7bc26362ac3797 (HEAD -> 146.0.7680.71, tag: 146.0.7680.71)
Author: Roger McFarlane <[email protected]>
Date:   Mon Mar 9 12:52:01 2026 -0700

    [M146-desktop-respin] Make LimitedLayerEntropyCostTracker time-aware.
    
    This change modifies the LimitedLayerEntropyCostTracker to account for
    the entropy cost of studies that are active at a specific evaluation
    time. The evaluation time is passed to the tracker's constructor and is
    used to check against the study's filter dates and Google web visibility
    dates.
    
    The current time for entropy evaluation is sourced from
    VariationsIdsProvider.
    
    (cherry picked from commit 2ec2c50b47686def251947a2675a207863803cac)
    
    Bug: 490248046, 490432663
    Change-Id: I3174730f35b037d533bf10b2b1d0531e3781acfe
    Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7639358
    Reviewed-by: Alexei Svitkine <[email protected]>
    Commit-Queue: Alexei Svitkine <[email protected]>
    Cr-Original-Commit-Position: refs/heads/main@{#1595543}
    Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7637760
    Bot-Commit: Rubber Stamper <[email protected]>
    Cr-Commit-Position: refs/branch-heads/7680_65@{#23}
    Cr-Branched-From: efe36a9d42443b4091a5be1be21e93ceff9b7a5e-refs/branch-heads/7680@{#1898}
    Cr-Branched-From: 76b7d80e5cda23fe6537eed26d68c92e995c7f39-refs/heads/main@{#1582197}

Build args

# Set build arguments here. See `gn help buildargs`.
is_official_build = false
is_debug = true  
symbol_level = 2
v8_symbol_level = 2
blink_symbol_level = 2
is_component_build = false  
proprietary_codecs = true   
ffmpeg_branding = "Chrome"  
v8_enable_sandbox = true
dcheck_always_on = true
optimize_webui = true
target_os = "linux"
target_cpu = "x64"

Usage

  1. Apply the two patch files to a vulnerable version of Chromium.
  2. Open browser chrome <path>/trigger.html

Abort

gen/third_party/libc++/src/include/__memory/unique_ptr.h:578: libc++ Hardening assertion __checker_.__in_bounds<deleter_type>(std::__to_address(__ptr_), __i) failed: unique_ptr<T[]>::operator[](https://github.com/jaf0rk/cve-2026-3909/blob/main/index): index out of range
Received signal 6
Download Tool