CVE-2026-6308: Out of bounds read in Media
Chromium: CVE-2026-6308 Out of bounds read in Media
Other sources
Out of bounds read in Media in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-6308?
CVE-2026-6308 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2026-6308?
To fix CVE-2026-6308, update Google Chrome to version 147.0.7727.101 or later.
Who is affected by CVE-2026-6308?
CVE-2026-6308 affects Google Chrome versions prior to 147.0.7727.101.
Can CVE-2026-6308 be exploited by remote attackers?
Yes, CVE-2026-6308 can be exploited by remote attackers via crafted HTML pages that manipulate UI gestures.
Is CVE-2026-6308 relevant to Microsoft Edge and operating systems?
CVE-2026-6308 is relevant to certain versions of Microsoft Edge based on Chromium, while not affecting the underlying operating systems directly.