CVE-2026-6302Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-04-16)
  • 4 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-15: 1Mentions · 2026-04-16: 3PoC Mentioned / Linked · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 304-1504-16
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-163
Disclosure3
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6302 Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium… https://www.cve.org/CVERecord?id=CVE-2026-6302 ----- Traducción: CVE-2026-6302: us… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑6302, describing a use‑after‑free in Chrome’s Video component that could allow remote code execution via crafted HTML.

    0000029
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6302 Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium… https://www.cve.org/CVERecord?id=CVE-2026-6302

    Post summary

    The snippet announces CVE-2026-6302, detailing a use-after-free flaw in Chrome’s video handling that could lead to arbitrary code execution via a crafted HTML page.

    00000229
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6302 Use After Free in Google Chrome Video Prior to 147.0.7727.101 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6302

    Post summary

    CVE-2026-6302 is a use-after-free vulnerability affecting Google Chrome’s video handling in versions before 147.0.7727.101.

    0000054
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6302 Use after free in Video in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code in… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6302 #Google #CyberSecurity #InfoSec

    Post summary

    This tweet announces a high‑severity use‑after‑free flaw (CVE‑2026‑6302) in Google Chrome that could allow remote code execution, provides a CVSS score, and links to a full technical analysis.

    000001
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more