Vulnerability Details CVE-2026-6358
Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.8%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-6358
-
cpe:2.3:a:google:chrome:38.0.2125.101
-
cpe:2.3:a:google:chrome:40.0.2214.109
-
cpe:2.3:a:google:chrome:40.0.2214.89
-
cpe:2.3:a:google:chrome:42.0.2311.107
-
cpe:2.3:a:google:chrome:54.0.2840.68
-
cpe:2.3:a:google:chrome:83.0.4103.106