CVE-2026-6307

8.8

Google · Chrome

A type confusion vulnerability in the Google Chrome Turbofan component allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A high-severity type confusion vulnerability in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution through specially crafted web content.

Vulnerability

This flaw involves a type confusion error within the Turbofan JIT compiler component. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a malicious HTML page, potentially resulting in code execution within the browser sandbox.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for significant impact on client-side security. Successful exploitation could lead to full compromise of the user browser environment, facilitating data theft, session hijacking, or further lateral movement within the corporate network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 147.0.7727.101 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Monitor endpoint logs for unusual browser activity, process crashes, or unexpected network connections originating from the Chrome browser process.

Compensating Controls: Ensure that enterprise endpoint protection software is active and configured to block execution of suspicious scripts or unauthorized binary downloads from untrusted web sources.

Exploitation status

Public Exploit Available: Yes, multiple public proof-of-concept repositories exist on GitHub as of April 2026.

Analyst recommendation

Given the prevalence of public proof-of-concept material and the high-severity nature of arbitrary code execution flaws in web browsers, organizations must prioritize the deployment of the Chrome update. Failure to patch will leave end-user systems exposed to drive-by download attacks that bypass conventional security perimeters.

More Google CVEs

Sources