PatchSiren cyber security CVE debrief
CVE-2026-6304 Google CVE debrief
A use-after-free vulnerability in the Graphite font rendering library within Google Chrome enables sandbox escape from a compromised renderer process. The flaw was addressed in Chrome 147.0.7727.101, released April 2026. The CVSS 3.1 score of 8.3 reflects high impact across confidentiality, integrity, and availability, with attack complexity rated as high due to the prerequisite renderer compromise. No known exploitation in ransomware campaigns has been documented.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-15
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-04-15
- Advisory updated
- 2026-05-26
Who should care
Organizations with managed Chrome deployments, security teams responsible for browser security posture, and incident responders tracking renderer exploitation chains
Technical summary
The vulnerability exists in Chrome's integration of the Graphite font rendering library, where a use-after-free condition can be triggered through crafted HTML content. Successful exploitation requires prior compromise of the renderer process, after which the memory corruption flaw may allow escape from Chrome's sandbox security boundary. The fix was included in the stable channel update released April 15, 2026.
Defensive priority
high
Recommended defensive actions
- Upgrade Google Chrome to version 147.0.7727.101 or later across all managed endpoints
- Verify automatic update mechanisms are functional for Chrome installations
- Review browser isolation policies to limit renderer process compromise impact
- Monitor for anomalous renderer crashes or unexpected sandbox escape attempts
- Audit endpoints for Chrome versions prior to 147.0.7727.101
- resourceLinkAnnotations:ref-4
Evidence notes
The CVE description and NVD record identify Google Chrome as the affected product, with remediation in version 147.0.7727.101. The vendor field indicates Apple with medium confidence based on NVD CPE data; this appears to reflect macOS as an affected platform rather than the vulnerability origin. The Chrome Release Notes confirm the fix date and severity classification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6304 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6304
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6304 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6304
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/496393742
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.