Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6362

19
FAUCET Score

CVE-2026-6362 is a use-after-free vulnerability in the Codecs component of Google Chrome versions prior to 147.0.7727.101. This memory safety flaw can be triggered by a remote attacker through a specially crafted video file, potentially enabling out-of-bounds memory access. The vulnerability has a CVSS score of 6.3 (Medium severity) with a network-based attack vector requiring minimal complexity and user interaction, such as opening a malicious video. The potential impacts include information disclosure, data integrity compromise, and availability disruption, though the scope remains unchanged to the vulnerable component. There is currently no evidence of active exploitation, as the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on public exploit tracking lists. The EPSS score of 0.00017 indicates very low probability of exploitation in the wild, suggesting this remains a theoretical risk rather than an immediate threat. However, organizations should prioritize patching to Chrome 147.0.7727.101 or later as part of standard security maintenance procedures.

Impacted Technologies

VendorProductVersion(s)CPE
>= 147.0.7727.101, < 147.0.7727.101CPE match
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
< 147.0.7727.101CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 13th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Microsoft Edge (Chromium-based)Fixed in: 147.0.3912.72
googlevendor investigatingvia chrome_releases
View patch

Vendor Advisories (2)

microsoft2026-Apr/CVE-2026-6362

Chromium: CVE-2026-6362 Use after free in Codecs

Apr 14, 2026
googlegoogle:chrome-7d655429efb624cbCRITICAL

Stable Channel Update for ChromeOS / ChromeOS Flex

References

chromereleases.googleblog.com / 2026/04/stable-channel-update-for-desktop_15.html
Vendor Advisory
issues.chromium.org / issues/500066234
Issue TrackingPermissions Required