Vulnerability · NVD
CVE-2026-6358
CVE-2026-6358, high severity (CVSS 8.8): 1 tracked app concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 8.8
- Exploitation
- 0.3 %
- Tracked apps
- 1
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical)
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.35%
exploit very unlikely
percentile 25.2%
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
-
Observed affected builds (27)
147.0.7727.50 146.0.7680.177 146.0.7680.120 143.0.7499.146 142.0.7444.158 139.0.7258.160 138.0.7204.179 138.0.7204.157 138.0.7204.63 136.0.7103.88 132.0.6834.123 130.0.6723.102 129.0.6668.100 123.0.6312.40 120.0.6099.144 119.0.6045.163 118.0.5993.111 114.0.5735.196 114.0.5735.131 109.0.5414.117 103.0.5060.70 102.0.5005.98 90.0.4430.91 88.0.4324.181 88.0.4324.152 87.0.4280.141 70.0.3538.80
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome Android
|
Android | <147.0.7727.101 | cpe:2.3:a:google:chrome:*:*:*:*:*:android:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.