Junglewise Threat Intelligence

CVE-2026-6364: Google Chrome out of bounds read in Skia

CVE-2026-6364 · Severity: medium · CVSS 6.5 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics engine could allow a remote attacker to access sensitive information from the browser's memory if a user opens a specially crafted file. This could lead to the exposure of private data or help facilitate further attacks against the user's system.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Skia graphics component of Google Chrome. The flaw is triggered when the browser processes a specially crafted file, leading to memory access outside of the intended buffer. A remote, unauthenticated attacker can exploit this by inducing a user to open a malicious file or visit a compromised website, potentially resulting in the disclosure of sensitive information from the browser's process memory. The issue is addressed in Google Chrome version 147.0.7727.101.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: advisory
  • 2026-04-15: patched: Fixed in version 147.0.7727.101

References

Related threats