"Use-after-free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page."
How Samsung achieves this is through pixel-level light control, adjusting its OLED emission so that light only shines toward the user when facing directly at the phone screen. As you pan left and right, the part of the Privacy Display that you can set to block sensitive notifications, 2FA codes, and more fades to black. Notably, the feature wouldn't reduce the phone's overall brightness or color depth, unlike a physical privacy screen protector.
CVE-2026-3909 is an out-of-bounds write flaw in Skia, the graphics library Chrome uses to render web content and parts of its user interface. Memory corruption bugs like this can sometimes be abused by attackers to crash applications or run their own code if successfully exploited.
This fix associated with the Coruna exploit was shipped in iOS 17.2 on December 11th, 2023. This update brings that fix to devices that cannot update to the latest iOS version.