MEDIUM
chromium-browser: skia: chromium-browser: skia: Out of bounds read in Skia
Published Apr 15, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.25%
Description
Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted file. (Chromium security severity: Medium)
Affected products
-
- Version 147.0.7727.101StatusaffectedConstraints<147.0.7727.101
- Version
No data.
Red Hat Enterprise Linux 6
webkitgtk
Out of support scope
Red Hat Enterprise Linux 7
webkitgtk3
Affected
Red Hat Enterprise Linux 7
webkitgtk4
Affected
Red Hat Enterprise Linux 8
webkit2gtk3
Affected
Red Hat Enterprise Linux 9
webkit2gtk3
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | webkitgtk | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk3 | Affected | n/a |
| Red Hat Enterprise Linux 7 | webkitgtk4 | Affected | n/a |
| Red Hat Enterprise Linux 8 | webkit2gtk3 | Affected | n/a |
| Red Hat Enterprise Linux 9 | webkit2gtk3 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2026-6364 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2458786 Issue Tracking
- https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html Vendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23094 Advisory
- https://issues.chromium.org/issues/502103414 Issue TrackingPermissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2026-6364
- https://www.cve.org/CVERecord?id=CVE-2026-6364
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-6364 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2458786 | Issue Tracking | |
| https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html | Vendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23094 | Advisory | |
| https://issues.chromium.org/issues/502103414 | Issue TrackingPermissions Required | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-6364 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-6364 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Chrome
Published Apr 15, 2026
Updated May 26, 2026
Reserved Apr 15, 2026
Link CVE-2026-6364
CISA Vulnrichment
Updated Apr 16, 2026
ENISA EUVD
EUVD-2026-23094 Assigner Chrome
Published Apr 15, 2026
Updated May 26, 2026
Exploited since n/a
Link EUVD-2026-23094