CVE-2026-6363
published 2026-04-15CVE-2026-6363: Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML…
PriorityP350high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.27%
19.7th percentile
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 147.0.7727.101 | 147.0.7727.101 | |
| chrome | >= 147.0.7727.101 < 147.0.7727.101 | 147.0.7727.101 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 147.0.7727.55 V8 type confusion (ID 495751)
vuldb·2026-04-16·CVSS 8.8
CVE-2026-6363 [HIGH] Google Chrome up to 147.0.7727.55 V8 type confusion (ID 495751)
A vulnerability has been found in Google Chrome and classified as critical. This issue affects some unknown processing of the component V8. Performing a manipulation results in type confusion.
This vulnerability is identified as CVE-2026-6363. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
GHSA-mvj2-3qfg-7mxp: Type Confusion in V8 in Google Chrome prior to 147
ghsa_unreviewed·2026-04-15
CVE-2026-6363 [HIGH] CWE-843 GHSA-mvj2-3qfg-7mxp: Type Confusion in V8 in Google Chrome prior to 147
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Red Hat
chromium-browser: Type Confusion in V8
vendor_redhat·2026-04-15·CVSS 8.8
CVE-2026-6363 [HIGH] CWE-843 chromium-browser: Type Confusion in V8
chromium-browser: Type Confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=495751197
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-6363
vendor_chrome·2026-04-15·CVSS 8.8
CVE-2026-6363 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-6363
Stable Channel Update for Desktop
CVE-2026-6363: Type Confusion in V8. Reported by Google on 2026-03-24 [TBD][ 495996858 ] Medium CVE-2026-6318: Use after free in Codecs
Reported by Syn4pse on 2026-03-25 [TBD][ 499018889 ] Medium CVE-2026-6319: Use after free in Payments
Severity: medium
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-
bugzilla·2026-04-17·CVSS 8.8
CVE-2026-6299 [HIGH] CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-
CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-2026-6363 ... chromium: various flaws [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-
bugzilla·2026-04-17·CVSS 8.8
CVE-2026-6299 [HIGH] CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-
CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-2026-6363 ... chromium: various flaws [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6363 V8: Google Chrome: Chromium: Google Chrome V8: Out-of-bounds memory access via crafted HTML page
bugzilla·2026-04-15·CVSS 8.8
CVE-2026-6363 [HIGH] CVE-2026-6363 V8: Google Chrome: Chromium: Google Chrome V8: Out-of-bounds memory access via crafted HTML page
CVE-2026-6363 V8: Google Chrome: Chromium: Google Chrome V8: Out-of-bounds memory access via crafted HTML page
Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
2026-04-15
Published