CVE-2026-6313 is a Cross-Origin Resource Sharing (CORS) policy enforcement flaw in Google Chrome versions prior to 147.0.7727.101 that permits unauthorized cross-origin data leakage. An attacker who has successfully compromised the renderer process can exploit this vulnerability by serving a crafted HTML page to extract sensitive data from cross-origin sources. This vulnerability carries a Chromium security severity rating of High. The attack requires network access and user interaction, with high complexity due to the prerequisite of renderer process compromise. The CVSS 3.1 score of 3.1 (Low) reflects limited impact, as the vulnerability only enables confidentiality breaches without affecting system integrity or availability. The attack surface is restricted to users who encounter the malicious HTML content while running the vulnerable Chrome version. Exploitation status indicates this vulnerability is not currently being actively exploited in the wild, with no public exploit code readily available and minimal community attention. The vulnerability maintains an inactive status on KEV tracking systems, and the exceptionally low EPSS score of 0.0001 suggests negligible real-world exploitation risk at this time. Users should update to Chrome 147.0.7727.101 or later to remediate the vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.