CVE-2026-6360
vulnerability analysis and mitigation

Overview

CVE-2026-6360 is a use-after-free vulnerability in the FileSystem component of Google Chrome that allows a remote attacker to potentially exploit object corruption via a crafted HTML page. It was reported by security researcher asjidkalam on March 31, 2026, and publicly disclosed on April 15, 2026, as part of a 31-fix Chrome stable channel update. All Google Chrome versions prior to 147.0.7727.101 are affected, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), arising from improper memory management in Chrome's FileSystem component where a memory region is freed but subsequently referenced, enabling object corruption (GitHub Advisory, Feedly). The attack vector is network-based with low complexity, requiring no privileges but necessitating user interaction — specifically, a victim visiting or opening a crafted HTML page. The Chromium issue tracker entry is tracked under bug ID 497880137, though full technical details remain restricted pending broad user patch adoption (Chrome Releases). No public proof-of-concept exploit code has been identified at this time (Feedly).

Impact

Successful exploitation could allow a remote attacker to achieve arbitrary code execution or cause a denial of service within the Chrome renderer process by corrupting heap memory through the dangling pointer. Given the CVSS scores of High across confidentiality, integrity, and availability, a fully weaponized exploit could result in complete compromise of the browser context, potential sandbox escape, and access to sensitive user data. The attack scope is limited to the browser process itself (Scope: Unchanged), but chaining with a sandbox escape could extend impact to the underlying operating system (GitHub Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.027–0.028%, placing it in the 8th percentile for exploitation likelihood within 30 days (GitHub Advisory). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 147.0.7727.101 on Windows, macOS, or Linux, or Microsoft Edge (Chromium-based) on unpatched versions.
  2. Craft malicious HTML page: Develop a specially crafted HTML page that triggers a use-after-free condition in Chrome's FileSystem API implementation, causing the browser to reference freed memory.
  3. Deliver payload: Host the crafted HTML page on an attacker-controlled server or distribute it via phishing emails, malicious advertisements, or compromised websites to lure the victim into opening it.
  4. Trigger memory corruption: When the victim opens the page in a vulnerable Chrome instance, the FileSystem component frees a memory object but continues to reference it, resulting in heap corruption.
  5. Achieve code execution: By controlling the freed memory region (heap spray or similar technique), the attacker can redirect execution flow to attacker-controlled code, potentially achieving arbitrary code execution within the Chrome renderer sandbox.
  6. Optional sandbox escape: Chain with an additional sandbox escape vulnerability to gain full OS-level code execution beyond the browser sandbox (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the Chrome browser process to unknown or suspicious IP addresses following a web page visit; HTTP requests to newly registered or low-reputation domains serving HTML content.
  • Process: Unusual child processes spawned by chrome.exe or chromium (e.g., cmd.exe, powershell.exe, bash, curl) that are not typical browser subprocesses; Chrome renderer processes crashing repeatedly with heap corruption errors.
  • Logs: Browser crash reports or minidumps referencing FileSystem-related stack traces; Windows Event Logs showing unexpected process creation events originating from Chrome.
  • File System: Unexpected files written to user profile directories or temp folders by the Chrome process; new scheduled tasks or persistence mechanisms created shortly after a browser session.

Mitigation and workarounds

Google has released a patch in Chrome 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac), which addresses this vulnerability along with 30 other security fixes (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update via the Microsoft Security Response Center (Microsoft MSRC). Organizations should enable automatic Chrome updates, prioritize patching in high-risk environments, and educate users to avoid opening HTML files or links from untrusted sources until all instances are updated. No configuration-based workaround is available; updating to the patched version is the only remediation.

Community reactions

The CIS (Center for Internet Security) issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-6360, could allow for arbitrary code execution, urging prompt patching (Feedly). Security outlets including CyberPress and CyberNoz covered the broader Chrome update, highlighting the 31-vulnerability patch batch and the risk of arbitrary code execution. F5 Labs included this CVE in their weekly threat bulletin for April 22, 2026. Community discussion on Bluesky and Mastodon noted the high severity rating and the breadth of the Chrome update, though no significant controversy or researcher-specific commentary on this individual CVE was observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 147.0.7727.101-1~deb12u1

Fixed

sid

chromium: 147.0.7727.101-1

Fixed

trixie

chromium: 147.0.7727.101-1~deb13u1

Fixed

Alpine

Fixed

edge

qt6-qtwebengine: 6.11.0-r4

Fixed

v3.23

qt6-qtwebengine: 6.10.3-r2

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management