CYBERSECURITY & PRIVACY — 2026-03-17
Google Patches Two Actively Exploited Chrome Zero-Days in Skia and V8
Google patched two Chrome zero-days exploited in the wild, affecting the Skia graphics library and V8 JavaScript engine. CISA added both to its Known Exploited Vulnerabilities catalog on March 13, mandating federal agency patching within 21 days. The dual exploit chain suggests sophisticated actor capability—Skia for initial rendering compromise, V8 for sandbox escape.