Junglewise Threat Intelligence

CVE-2026-6302: Google Chrome use after free in Video

CVE-2026-6302 · Severity: high · CVSS 8.8 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's video processing component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the attack is limited by Chrome's security sandbox, it still poses a significant risk to data privacy and system integrity.

Technical details

A use-after-free vulnerability exists in the Video component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of video content. A remote, unauthenticated attacker can exploit this by inducing a user to load a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chrome renderer sandbox. This issue was resolved in version 147.0.7727.101 for Linux and 147.0.7727.101/102 for Windows and Mac.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-24: disclosed: Reported by Syn4pse
  • 2026-04-15: patched: Fixed in version 147.0.7727.101/102
  • 2026-04-15: advisory

References