CVE-2026-6299
Google · Chrome
A use-after-free vulnerability in the Prerender component of Google Chrome prior to version 147 could allow a remote attacker to execute arbitrary code.
Executive summary
A use-after-free vulnerability in the Prerender component of Google Chrome poses a significant risk of remote code execution for all users.
Vulnerability
The vulnerability exists in the Prerender component, which can be triggered by a specially crafted website. An attacker can use this flaw to corrupt memory and gain control over the application's execution flow.
Business impact
With a CVSS score of 8.8, this vulnerability allows for high-impact compromise of end-user workstations. Successful exploitation could lead to unauthorized access to internal systems and sensitive corporate information handled by the browser.
Remediation
Immediate Action: Update Google Chrome to version 147 or later immediately.
Proactive Monitoring: Review endpoint protection logs for anomalous browser activity or unexpected crashes.
Compensating Controls: Enforce strict organizational policies regarding website access and endpoint security hardening.
Exploitation status
Public Exploit Available: false
Analyst recommendation
The frequency of browser-based vulnerabilities requires a proactive patching strategy. IT administrators should prioritize the deployment of Chrome 147 across the enterprise to remediate this critical memory safety issue.