CVE-2026-6360 is a use-after-free vulnerability in the FileSystem component of Google Chrome versions prior to 147.0.7727.101 that could allow remote attackers to exploit object corruption through a malicious HTML page. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring minimal user interaction, posing significant risks to confidentiality, integrity, and availability. Exploitation is currently not documented in active threat campaigns, with the CVE absent from the Known Exploited Vulnerabilities catalog and showing low probability of exploitation based on the EPSS score of 0.000240. The vulnerability has not generated significant community attention and is not tracked on industry hot lists. Users of affected Chrome versions should prioritize patching to version 147.0.7727.101 or later to remediate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.