
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6302 is a use-after-free vulnerability in the Video component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. The vulnerability was reported by researcher Syn4pse on 2026-03-24 and publicly disclosed on 2026-04-15 as part of a 31-fix Chrome stable channel update. It affects all versions of Google Chrome prior to 147.0.7727.101, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), occurring in Chrome's Video component when memory that has already been freed is subsequently accessed or dereferenced (GitHub Advisory). Exploitation requires the victim to visit a maliciously crafted HTML page containing specially designed video content, triggering the use-after-free condition in the browser's video processing pipeline. The attack vector is network-based with low complexity and no privileges required, though user interaction (visiting the malicious page) is necessary. The Chromium issue tracker entry is referenced as issue 495477995, though full bug details remain restricted pending broad user adoption of the patch (Chrome Release).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, resulting in high confidentiality, integrity, and availability impact on the affected browser process. While execution is confined to the sandbox, this can serve as a stepping stone for sandbox escape chains, potentially enabling broader system compromise. Affected users risk unauthorized data access, browser session hijacking, and application crashes (GitHub Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.056% (18th percentile), indicating a relatively low near-term exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
<video> elements or media source extensions) designed to trigger a use-after-free condition in Chrome's Video component.cmd.exe, powershell.exe, /bin/sh, curl, wget); Chrome renderer crashes or unexpected restarts correlated with video playback.Google has released the fix in Chrome version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac); all users should update immediately (Chrome Release). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update as well (Microsoft MSRC). As an interim measure, enabling Chrome's automatic update feature ensures timely patch delivery; organizations may also consider restricting access to untrusted websites or disabling HTML5 video playback via policy until patching is complete. Linux distributions including Fedora, openSUSE, and Debian have also released updated Chromium packages.
The CIS issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-6302, could allow for arbitrary code execution, urging prompt updates. Security media outlets including CyberPress and CyberNoz covered the broader Chrome update, highlighting the 31-fix release and the risk of sandbox code execution. The F5 Labs weekly threat bulletin for April 22, 2026 also referenced the Chrome vulnerability batch. Community discussion on Mastodon and other platforms noted the high volume of use-after-free bugs addressed in this release.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."