Vulnérabilité · NVD
CVE-2026-6358
CVE-2026-6358, sévérité high (CVSS 8.8) : 1 app suivie concernée, toutes corrigées ou à statut indéterminable en version courante.
- Gravité (CVSS)
- 8.8
- Exploitation
- 0.3 %
- Apps suivies
- 1
- Encore exposées
- 0
Échelle NVD
EPSS, prédiction à 30 jours
EN Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Critical)
Vecteur d'attaque : Réseau
Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
0.29%
exploit très peu probable
percentile 21.2%
Apps suivies liées à cette CVE
Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.
-
Builds affectées observées (27)
147.0.7727.50 146.0.7680.177 146.0.7680.120 143.0.7499.146 142.0.7444.158 139.0.7258.160 138.0.7204.179 138.0.7204.157 138.0.7204.63 136.0.7103.88 132.0.6834.123 130.0.6723.102 129.0.6668.100 123.0.6312.40 120.0.6099.144 119.0.6045.163 118.0.5993.111 114.0.5735.196 114.0.5735.131 109.0.5414.117 103.0.5060.70 102.0.5005.98 90.0.4430.91 88.0.4324.181 88.0.4324.152 87.0.4280.141 70.0.3538.80
Configurations CPE vulnérables (1)
| Vendor | Produit | Plateforme | Versions | CPE 2.3 URI |
|---|---|---|---|---|
|
chrome Android
|
Android | <147.0.7727.101 | cpe:2.3:a:google:chrome:*:*:*:*:*:android:*:* |