CVE-2026-6308

7.5

Google · Chrome

An out of bounds read vulnerability exists in Google Chrome Media components, allowing a remote attacker to execute arbitrary code via a crafted HTML page and specific user interaction.

Executive summary

A critical out of bounds read vulnerability in Google Chrome allows remote code execution through user interaction, necessitating immediate browser updates.

Vulnerability

This vulnerability is an out of bounds read (CWE-125) located within the browser Media component. It requires an unauthenticated remote attacker to convince a user to engage in specific UI gestures while visiting a malicious webpage to trigger arbitrary code execution.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational security, as it could lead to full system compromise, data theft, or the installation of malware on endpoints. With a CVSS score of 7.5, this high severity vulnerability represents a significant threat to workstation integrity and internal network security if workstations are used to access sensitive corporate resources.

Remediation

Immediate Action: Update all Google Chrome installations to version 147.0.7727.101 or later immediately.

Proactive Monitoring: Monitor endpoint logs for unusual browser activity, unexpected child processes spawned by the browser, or network connections to known malicious domains.

Compensating Controls: Deploy endpoint detection and response tools to identify and block suspicious process execution patterns originating from the browser environment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution, security teams must prioritize the deployment of the latest Chrome security updates across the enterprise. Failure to patch these endpoints leaves the organization vulnerable to browser based attacks that can bypass standard security perimeters. Ensure all users are prompted to restart their browsers to apply the update immediately.

More Google CVEs

Sources