CVE-2026-6300

Google · Chrome

A use-after-free vulnerability in the CSS engine of Google Chrome prior to version 147 could allow remote code execution through malicious web content.

Executive summary

A use-after-free vulnerability in the Google Chrome CSS engine allows remote attackers to potentially execute arbitrary code via malformed web content.

Vulnerability

The CSS engine fails to properly manage memory, leading to a use-after-free condition. An attacker can craft a website that forces the browser to access freed memory, resulting in code execution.

Business impact

Given the prevalence of Chrome in enterprise environments, a CVSS score of 8.8 signifies an urgent risk. Compromise of a browser leads to the loss of confidentiality and integrity of web-based applications and user data.

Remediation

Immediate Action: Update Google Chrome to version 147 or later.

Proactive Monitoring: Use centralized management tools to verify the browser version across all company endpoints.

Compensating Controls: Deploy advanced threat protection solutions that can detect and block browser exploitation attempts.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Patching browser software is one of the most effective ways to reduce the risk of client-side attacks. Organizations must ensure that the update to Chrome 147 is pushed to all workstations immediately.