
🎥 CVE‑2026‑6362 – Google Chrome Codecs RCE (High): In Google Chrome prior to 147.0.7727.101, a use‑after‑free in the Codecs component allows remote attackers to trigger out‑of‑bounds memory access via a crafted video file, which can be delivered through any web page rendering media, leading to code execution inside the browser sandbox. CVSS 8.8 (v3.0), published 2026‑04‑16; mitigated by updating to Chrome 147.0.7727.101 or later. https://www.tenable.com/cve/CVE-2026-6362 #CVE20266362 #Chrome #Media #RCE #BrowserSecurity
Post summary
CVE‑2026‑6362 is a high‑severity remote code execution vulnerability in Chrome’s codecs via a use‑after‑free; it is mitigated by updating to Chrome 147.0.7727.101 or later.



