CVE-2026-6298Disclosure(apple / chrome)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Critical)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-15); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 104-1504-1604-21
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-161
Disclosure1
2026-04-211
Patch1
Full discourse3 posts
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-6298)[495700484][Skia]Heap-BoF https://skia-review.googlesource.com/c/skia/+/1199497 Reported by 86ac1f1587b71893ed2ad792cd7dde32

    Post summary

    A new heap buffer overflow vulnerability (CVE‑2026‑6298) in the Skia graphics library has been disclosed, with a source‑review link but no exploit details or patch information provided.

    000531.4K
    5.0K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chrome 147で31件の脆弱性を修正、Criticalは5件(CVE-2026-6296、CVE-2026-6297、CVE-2026-6298、CVE-2026-6299、CVE-2026-6358を) https://rocket-boys.co.jp/security-measures-lab/critical-flaws-fixed-in-google-chrome-147-update/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Google released Chrome 147, patching 31 vulnerabilities, including five critical CVEs (CVE‑2026‑6296 through CVE‑2026‑6358).

    00010107
    381 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6298 Heap buffer overflow in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a cr… https://www.cve.org/CVERecord?id=CVE-2026-6298

    Post summary

    The snippet announces CVE-2026-6298, a heap buffer overflow in Skia inside Google Chrome before 147.0.7727.101, providing technical details but no exploit, patch, or active exploitation evidence.

    0000069
    57.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more