CVE-2026-6309

8.3

Google · Chrome

A use after free vulnerability in the Viz component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome allows remote attackers to escape the browser sandbox, posing a significant risk to system integrity.

Vulnerability

This is a use after free flaw within the Viz component of the browser. It requires a remote attacker to compromise the renderer process and trick a user into interacting with a crafted HTML page, as indicated by the CVSS vector's requirement for user interaction.

Business impact

The ability to escape the browser sandbox represents a critical security failure, as it allows an attacker to bypass browser-level protections and potentially execute code on the underlying host operating system. Given the CVSS score of 8.3, this vulnerability poses a high risk of total system compromise, data exfiltration, or the installation of persistent malicious software. Organizations should prioritize remediation to prevent the loss of confidentiality and integrity of endpoint devices.

Remediation

Immediate Action: Update all instances of Google Chrome to version 147.0.7727.101 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for unusual browser process behavior or unauthorized attempts to access system-level files from the browser environment.

Compensating Controls: Ensure users are operating with the least privilege necessary, as this limits the potential damage if the sandbox is successfully escaped.

Exploitation status

Public Exploit Available: No confirmed public exploit (exploit_available: false).

Analyst recommendation

The severity of a sandbox escape vulnerability cannot be overstated, as it serves as a gateway to full system compromise. Security teams must ensure that automatic updates are enabled and verify that all Chrome installations are updated to the patched version. Given the potential for high-impact exploitation, this update should be treated as a priority task in the current patch cycle.

More Google CVEs

Sources