Junglewise Threat Intelligence

CVE-2026-6298: Google Chrome heap buffer overflow in Skia

CVE-2026-6298 · Severity: medium · CVSS 4.3 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to access sensitive information from the browser's memory. This occurs when the browser processes a specially crafted web page, potentially leading to the exposure of private data from other open tabs or browser processes. Users are protected by updating to the latest version of the Chrome browser.

Technical details

A heap buffer overflow vulnerability exists in Skia, the open-source 2D graphics library used by Google Chrome. The flaw is triggered when the browser renders a specially crafted HTML page, allowing a remote, unauthenticated attacker to perform an out-of-bounds memory access. While the CVSS score provided by CISA-ADP (4.3) suggests a medium severity focused on information disclosure, Google has internally classified this specific issue as 'Critical' in their security release notes. The vulnerability is addressed in Chrome version 147.0.7727.101 for Linux and 147.0.7727.101/102 for Windows and Mac.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-24: disclosed: Reported to Chrome by external researcher
  • 2026-04-15: patched: Fixed in Chrome Stable channel update 147.0.7727.101/102
  • 2026-04-15: advisory: Initial NVD publication

References