
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6308 is a high-severity out-of-bounds read vulnerability in the Media component of Google Chrome. It was reported by Google's internal security team on March 29, 2026, and publicly disclosed on April 15, 2026, as part of a 31-fix stable channel update. The vulnerability affects Google Chrome versions prior to 147.0.7727.101 and Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 7.5 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's Media component. A remote attacker can exploit this flaw by crafting a malicious HTML page that triggers specific user interface gestures, causing the browser to read memory beyond the bounds of an allocated buffer during media processing. Successful exploitation requires user interaction (convincing the victim to engage in specific UI gestures) and has high attack complexity, but requires no privileges. The Chromium issue tracker reference is bug ID 497412658 (Chrome Releases, GitHub Advisory).
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the victim's system, potentially leading to full system compromise. The out-of-bounds read may expose sensitive memory contents, enabling information disclosure, and could also result in denial of service conditions. Given that Chrome runs with sandboxing, a full compromise would likely require chaining this vulnerability with a sandbox escape, though the memory disclosure itself poses significant risk (GitHub Advisory, Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability was reported internally by Google and is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039% (12th percentile), indicating a low near-term probability of exploitation (GitHub Advisory). No threat actor attribution has been identified.
Google has released a patch in Chrome version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac), which addresses this vulnerability along with 30 other security fixes. Microsoft has also released a corresponding update for Edge (Chromium-based). Users and administrators should update all Chrome and Edge installations to the patched versions immediately. As a general precaution, users should avoid visiting untrusted websites or opening media content from unknown sources until the update is applied (Chrome Releases, Microsoft).
The April 15, 2026 Chrome stable update received broad coverage from security outlets, with multiple publications noting the significance of the 31-fix release, which included five Critical-severity vulnerabilities alongside CVE-2026-6308. Coverage from outlets such as CyberNoz and CyberPress highlighted the arbitrary code execution risk posed by the batch of Chrome flaws. The CIS also issued an advisory noting that multiple vulnerabilities in Google Chrome could allow for arbitrary code execution, recommending immediate updates (CIS Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."