CVE-2026-6362Disclosure(google / chrome)

LOWCVSS 4.3 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file. (Chromium security severity: High)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-04-16)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-15: 1Mentions · 2026-04-16: 4Patch / Workaround · 2026-04-16: 2Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 304-1504-16
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-164
Disclosure3Patch1
Full discourse5 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🎥 CVE‑2026‑6362 – Google Chrome Codecs RCE (High): In Google Chrome prior to 147.0.7727.101, a use‑after‑free in the Codecs component allows remote attackers to trigger out‑of‑bounds memory access via a crafted video file, which can be delivered through any web page rendering media, leading to code execution inside the browser sandbox. CVSS 8.8 (v3.0), published 2026‑04‑16; mitigated by updating to Chrome 147.0.7727.101 or later. https://www.tenable.com/cve/CVE-2026-6362 #CVE20266362 #Chrome #Media #RCE #BrowserSecurity

    Post summary

    CVE‑2026‑6362 is a high‑severity remote code execution vulnerability in Chrome’s codecs via a use‑after‑free; it is mitigated by updating to Chrome 147.0.7727.101 or later.

    0001018
    855 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🎥 CVE‑2026‑6362 – Google Chrome Codecs RCE (High): In Google Chrome prior to 147.0.7727.101, a use‑after‑free in the Codecs component allows remote attackers to trigger out‑of‑bounds memory access via a crafted video file, which can be delivered through any web page rendering media, leading to code execution inside the browser sandbox. CVSS 8.8 (v3.0), published 2026‑04‑16; mitigated by updating to Chrome 147.0.7727.101 or later. https://www.tenable.com/cve/CVE-2026-6362 #CVE20266362 #Chrome #Media #RCE #BrowserSecurity

    Post summary

    CVE‑2026‑6362 is a high‑impact RCE in Chrome’s Codecs component caused by a use‑after‑free triggered by malformed video files; it can be resolved by upgrading to Chrome 147.0.7727.101 or newer.

    0000056
    855 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6362 Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted video file.… https://www.cve.org/CVERecord?id=CVE-2026-6362

    Post summary

    The text reports a use‑after‑free vulnerability (CVE‑2026‑6362) in Google Chrome codecs that could allow a remote attacker to cause out‑of‑bounds memory access by sending a crafted video file.

    00000129
    57.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Google Chrome (CVE-2026-6362) https://vuldb.com/vuln/357800

    Post summary

    The post announces the addition of CVE-2026-6362 to a vulnerability database, marking a new disclosure of a Google Chrome vulnerability.

    0000062
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6362 Use After Free in Google Chrome Codecs Prior to 147.0.7727.101 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6362

    Post summary

    The entry discloses a use-after-free vulnerability in Google Chrome codecs affecting versions before 147.0.7727.101.

    0000042
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more