CVE-2026-6299

Google · Chrome

A use-after-free vulnerability in the Prerender component of Google Chrome prior to version 147 could allow a remote attacker to execute arbitrary code.

Executive summary

A use-after-free vulnerability in the Prerender component of Google Chrome poses a significant risk of remote code execution for all users.

Vulnerability

The vulnerability exists in the Prerender component, which can be triggered by a specially crafted website. An attacker can use this flaw to corrupt memory and gain control over the application's execution flow.

Business impact

With a CVSS score of 8.8, this vulnerability allows for high-impact compromise of end-user workstations. Successful exploitation could lead to unauthorized access to internal systems and sensitive corporate information handled by the browser.

Remediation

Immediate Action: Update Google Chrome to version 147 or later immediately.

Proactive Monitoring: Review endpoint protection logs for anomalous browser activity or unexpected crashes.

Compensating Controls: Enforce strict organizational policies regarding website access and endpoint security hardening.

Exploitation status

Public Exploit Available: false

Analyst recommendation

The frequency of browser-based vulnerabilities requires a proactive patching strategy. IT administrators should prioritize the deployment of Chrome 147 across the enterprise to remediate this critical memory safety issue.