
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6360 is a use-after-free vulnerability in the FileSystem component of Google Chrome that allows a remote attacker to potentially exploit object corruption via a crafted HTML page. It was reported by security researcher asjidkalam on March 31, 2026, and publicly disclosed on April 15, 2026, as part of a 31-fix Chrome stable channel update. All Google Chrome versions prior to 147.0.7727.101 are affected, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), arising from improper memory management in Chrome's FileSystem component where a memory region is freed but subsequently referenced, enabling object corruption (GitHub Advisory, Feedly). The attack vector is network-based with low complexity, requiring no privileges but necessitating user interaction — specifically, a victim visiting or opening a crafted HTML page. The Chromium issue tracker entry is tracked under bug ID 497880137, though full technical details remain restricted pending broad user patch adoption (Chrome Releases). No public proof-of-concept exploit code has been identified at this time (Feedly).
Successful exploitation could allow a remote attacker to achieve arbitrary code execution or cause a denial of service within the Chrome renderer process by corrupting heap memory through the dangling pointer. Given the CVSS scores of High across confidentiality, integrity, and availability, a fully weaponized exploit could result in complete compromise of the browser context, potential sandbox escape, and access to sensitive user data. The attack scope is limited to the browser process itself (Scope: Unchanged), but chaining with a sandbox escape could extend impact to the underlying operating system (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.027–0.028%, placing it in the 8th percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
chrome.exe or chromium (e.g., cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses; Chrome renderer processes crashing repeatedly with heap corruption errors.Google has released a patch in Chrome 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac), which addresses this vulnerability along with 30 other security fixes (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update via the Microsoft Security Response Center (Microsoft MSRC). Organizations should enable automatic Chrome updates, prioritize patching in high-risk environments, and educate users to avoid opening HTML files or links from untrusted sources until all instances are updated. No configuration-based workaround is available; updating to the patched version is the only remediation.
The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-6360, could allow for arbitrary code execution, urging prompt patching (Feedly). Security outlets including CyberPress and CyberNoz covered the broader Chrome update, highlighting the 31-vulnerability patch batch and the risk of arbitrary code execution. F5 Labs included this CVE in their weekly threat bulletin for April 22, 2026. Community discussion on Bluesky and Mastodon noted the high severity rating and the breadth of the Chrome update, though no significant controversy or researcher-specific commentary on this individual CVE was observed.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."