PatchSiren cyber security CVE debrief
CVE-2026-6301 Google CVE debrief
A type confusion vulnerability in Google Chrome's Turbofan JavaScript compiler engine allows remote code execution via malicious HTML pages. The flaw affects Chrome versions prior to 147.0.7727.101 and carries a High severity rating from Chromium security. Type confusion in JIT compilers typically occurs when the engine incorrectly handles object types during optimization passes, leading to out-of-bounds memory access or use-after-free conditions that can be exploited for sandboxed code execution. The CVSS 3.1 score of 8.8 reflects network attack vector, low complexity, no privileges required, and high impact across confidentiality, integrity, and availability. The vulnerability was disclosed in April 2026 and modified in late May 2026, with official patches available through Chrome's stable channel update mechanism. No known exploitation in ransomware campaigns has been documented.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-15
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-04-15
- Advisory updated
- 2026-05-26
Who should care
Organizations relying on Google Chrome for business operations, security teams managing browser attack surface, and users handling sensitive data through web applications should prioritize this update due to the high exploitability and impact potential of JIT compiler vulnerabilities.
Technical summary
The vulnerability exists in Turbofan, Chrome's optimizing JIT compiler for JavaScript. Type confusion (CWE-843) arises when the compiler's type inference system produces incorrect assumptions about object types during speculative optimization, leading to memory safety violations. Successful exploitation requires user interaction with a crafted HTML page but results in arbitrary code execution within the renderer sandbox. The fix was released in Chrome stable channel update dated April 15, 2026.
Defensive priority
high
Recommended defensive actions
- Update Google Chrome to version 147.0.7727.101 or later through the browser's built-in update mechanism or official distribution channels
- Verify update installation by checking chrome://settings/help to confirm the running version meets or exceeds the patched release
- For managed enterprise environments, deploy the updated Chrome version through standard software distribution tools after testing compatibility with internal web applications
- Consider enabling site isolation and enhanced safe browsing features as defense-in-depth measures against similar renderer exploitation techniques
- Monitor for unusual renderer process crashes or unexpected sandbox escape attempts in browser security logs
Evidence notes
Vendor attribution to Apple in source data appears inconsistent with vulnerability description and CPE criteria, which identify Google Chrome as the affected product. Primary evidence sources are Chrome Release Notes and Chromium issue tracker.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6301 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6301
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6301 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6301
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/495273999
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.