CVE-2026-6308 — Out-of-bounds Read in Google Chrome
Severity
7.5HIGHCNA
No vectorEPSS
0.1%
top 76.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 15
Latest updateApr 16
Description
Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Affected Packages1 packages
🔴Vulnerability Details
3📋Vendor Advisories
2💬Community
1Bugzilla▶
CVE-2026-6308 Google Chrome: Chromium: Google Chrome: Arbitrary code execution via out-of-bounds read in Media component↗2026-04-15