CVE-2026-6314
8.3Google · Chrome
An out of bounds write vulnerability in the Google Chrome GPU process allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Executive summary
A high-severity out of bounds write vulnerability in Google Chrome allows remote attackers to perform a sandbox escape, posing a significant risk to system integrity.
Vulnerability
This flaw exists as an out of bounds write in the GPU process (CWE-787), which can be triggered by an unauthenticated remote attacker using a specially crafted HTML page to escape the browser sandbox.
Business impact
The ability to escape the browser sandbox represents a critical security failure, as it allows arbitrary code execution outside the restricted browser environment. With a CVSS score of 8.3, this high-severity vulnerability could lead to full system compromise, unauthorized data access, and the bypass of fundamental browser security controls.
Remediation
Immediate Action: Update all instances of Google Chrome to version 147.0.7727.101 or later immediately.
Proactive Monitoring: Monitor browser-related crash logs and security telemetry for unexpected process terminations or suspicious GPU-related activity.
Compensating Controls: Ensure that users are operating under the principle of least privilege, which limits the potential damage if a sandbox escape is successful, and maintain updated endpoint protection software.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS score and the nature of sandbox escape vulnerabilities, it is imperative that organizations prioritize the deployment of the latest Chrome security updates. Failure to patch these browsers leaves endpoints vulnerable to potentially severe remote code execution attacks that bypass standard security boundaries.