CVE-2026-6302
vulnerability analysis and mitigation

Overview

CVE-2026-6302 is a use-after-free vulnerability in the Video component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. The vulnerability was reported by researcher Syn4pse on 2026-03-24 and publicly disclosed on 2026-04-15 as part of a 31-fix Chrome stable channel update. It affects all versions of Google Chrome prior to 147.0.7727.101, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), occurring in Chrome's Video component when memory that has already been freed is subsequently accessed or dereferenced (GitHub Advisory). Exploitation requires the victim to visit a maliciously crafted HTML page containing specially designed video content, triggering the use-after-free condition in the browser's video processing pipeline. The attack vector is network-based with low complexity and no privileges required, though user interaction (visiting the malicious page) is necessary. The Chromium issue tracker entry is referenced as issue 495477995, though full bug details remain restricted pending broad user adoption of the patch (Chrome Release).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, resulting in high confidentiality, integrity, and availability impact on the affected browser process. While execution is confined to the sandbox, this can serve as a stepping stone for sandbox escape chains, potentially enabling broader system compromise. Affected users risk unauthorized data access, browser session hijacking, and application crashes (GitHub Advisory, Red Hat Bugzilla).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.056% (18th percentile), indicating a relatively low near-term exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 147.0.7727.101 or unpatched Microsoft Edge (Chromium-based) using browser fingerprinting techniques or social engineering.
  2. Craft malicious HTML page: Develop a web page containing specially crafted video content (e.g., manipulated HTML5 <video> elements or media source extensions) designed to trigger a use-after-free condition in Chrome's Video component.
  3. Deliver the payload: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing, malvertising, or a compromised website.
  4. Trigger the vulnerability: When the victim's browser processes the crafted video content, the use-after-free condition is triggered, causing memory corruption in the Video component.
  5. Achieve sandbox code execution: Leverage the memory corruption to redirect execution flow and run arbitrary code within the Chrome renderer sandbox, potentially chaining with a sandbox escape for full system access (Chrome Release, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Chrome browser process to unknown or suspicious IP addresses following video content rendering; HTTP/HTTPS requests to newly registered or low-reputation domains serving HTML pages with embedded video.
  • Process: Unusual child processes spawned by the Chrome renderer process (e.g., cmd.exe, powershell.exe, /bin/sh, curl, wget); Chrome renderer crashes or unexpected restarts correlated with video playback.
  • Logs: Browser crash reports or minidumps referencing the Video component; system event logs showing abnormal process creation originating from Chrome's renderer sandbox.
  • File System: Unexpected files written to user-accessible directories by Chrome renderer processes; new or modified browser extensions or configuration files following a suspicious browsing session.

Mitigation and workarounds

Google has released the fix in Chrome version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac); all users should update immediately (Chrome Release). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update as well (Microsoft MSRC). As an interim measure, enabling Chrome's automatic update feature ensures timely patch delivery; organizations may also consider restricting access to untrusted websites or disabling HTML5 video playback via policy until patching is complete. Linux distributions including Fedora, openSUSE, and Debian have also released updated Chromium packages.

Community reactions

The CIS issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-6302, could allow for arbitrary code execution, urging prompt updates. Security media outlets including CyberPress and CyberNoz covered the broader Chrome update, highlighting the 31-fix release and the risk of sandbox code execution. The F5 Labs weekly threat bulletin for April 22, 2026 also referenced the Chrome vulnerability batch. Community discussion on Mastodon and other platforms noted the high volume of use-after-free bugs addressed in this release.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 147.0.7727.101-1~deb12u1

Fixed

sid

chromium: 147.0.7727.101-1

Fixed

trixie

chromium: 147.0.7727.101-1~deb13u1

Fixed

Alpine

Fixed

edge

qt6-qtwebengine: 6.11.0-r4

Fixed

v3.23

qt6-qtwebengine: 6.10.3-r2

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management