CVE-2026-6362 is a use-after-free vulnerability in the Codecs component of Google Chrome versions prior to 147.0.7727.101. This memory safety flaw can be triggered by a remote attacker through a specially crafted video file, potentially enabling out-of-bounds memory access. The vulnerability has a CVSS score of 6.3 (Medium severity) with a network-based attack vector requiring minimal complexity and user interaction, such as opening a malicious video. The potential impacts include information disclosure, data integrity compromise, and availability disruption, though the scope remains unchanged to the vulnerable component. There is currently no evidence of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on public exploit tracking lists. The EPSS score of 0.00017 indicates very low probability of exploitation in the wild, suggesting this remains a theoretical risk rather than an immediate threat. However, organizations should prioritize patching to Chrome 147.0.7727.101 or later as part of standard security maintenance procedures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.