CVE-2026-6364Out-of-bounds Read in Google Chrome

CWE-125Out-of-bounds Read6 documents6 sources
Severity
4.3MEDIUM
No vector
EPSS
0.0%
top 92.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateApr 16

Description

Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium)

Affected Packages2 packages

CVEListV5google/chrome147.0.7727.101147.0.7727.101

🔴Vulnerability Details

2
VulDB
Google Chrome up to 147.0.7727.55 Skia out-of-bounds (ID 502103)2026-04-16
GHSA
GHSA-xm65-r32w-c46p: Out of bounds read in Skia in Google Chrome prior to 1472026-04-15

📋Vendor Advisories

2
Red Hat
chromium-browser: Out of bounds read in Skia2026-04-15
Chrome
Stable Channel Update for Desktop: CVE-2026-63642026-04-15

💬Community

1
Bugzilla
CVE-2026-6364 Skia: Google Chrome: Chromium: Skia: Information disclosure via out-of-bounds read in Google Chrome2026-04-15
CVE-2026-6364 — Out-of-bounds Read in Google Chrome | cvebase