cve-2026-6364

About this tag
CVE-2026-6364 is a security vulnerability in Google Chrome, specifically an out-of-bounds read in the Skia graphics library. This flaw could allow a remote attacker to extract sensitive information from process memory by tricking a user into opening a crafted file. The vulnerability affects Chrome versions prior to 147.0.7727.101. Google has released a patch, and Microsoft's Security Update Guide has also flagged the issue, indicating that the vulnerability may have broader implications beyond the browser. Users are advised to update Chrome to the latest version to mitigate the risk. The tag covers discussions about the vulnerability, its impact, and the necessary patching steps.
  1. Chrome Skia Out-of-Bounds Read CVE-2026-6364: Patch to 147.0.7727.101

    Google has patched a Skia out-of-bounds read in Chrome that maps to CVE-2026-6364, and the fix matters more than the severity label might suggest. The vulnerable builds are Google Chrome prior to 147.0.7727.101, and Google says a crafted file could let a remote attacker extract potentially...