Junglewise Threat Intelligence

CVE-2026-6360: Google Chrome use after free in FileSystem

CVE-2026-6360 · Severity: high · CVSS 8.8 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser's FileSystem component. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially leading to unauthorized access to data or the ability to run malicious code on the user's computer. This could result in the theft of sensitive information or a complete compromise of the user's browsing session.

Technical details

A use-after-free (UAF) vulnerability exists in the FileSystem API implementation within Google Chrome. The flaw is triggered when the browser incorrectly manages the lifecycle of memory objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can leverage this memory corruption to achieve arbitrary code execution within the context of the browser renderer process. The vulnerability is addressed in Google Chrome version 147.0.7727.101.

Affected products

  • Google Chrome versions prior to 147.0.7727.101

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: advisory
  • 2026-04-15: patched: Fixed in version 147.0.7727.101

References

Related threats