PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6304 Google CVE debrief

A use-after-free vulnerability in the Graphite font rendering library within Google Chrome enables sandbox escape from a compromised renderer process. The flaw was addressed in Chrome 147.0.7727.101, released April 2026. The CVSS 3.1 score of 8.3 reflects high impact across confidentiality, integrity, and availability, with attack complexity rated as high due to the prerequisite renderer compromise. No known exploitation in ransomware campaigns has been documented.

Vendor
Google
Product
Chrome
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-15
Original CVE updated
2026-05-26
Advisory published
2026-04-15
Advisory updated
2026-05-26

Who should care

Organizations with managed Chrome deployments, security teams responsible for browser security posture, and incident responders tracking renderer exploitation chains

Technical summary

The vulnerability exists in Chrome's integration of the Graphite font rendering library, where a use-after-free condition can be triggered through crafted HTML content. Successful exploitation requires prior compromise of the renderer process, after which the memory corruption flaw may allow escape from Chrome's sandbox security boundary. The fix was included in the stable channel update released April 15, 2026.

Defensive priority

high

Recommended defensive actions

  • Upgrade Google Chrome to version 147.0.7727.101 or later across all managed endpoints
  • Verify automatic update mechanisms are functional for Chrome installations
  • Review browser isolation policies to limit renderer process compromise impact
  • Monitor for anomalous renderer crashes or unexpected sandbox escape attempts
  • Audit endpoints for Chrome versions prior to 147.0.7727.101
  • resourceLinkAnnotations:ref-4

Evidence notes

The CVE description and NVD record identify Google Chrome as the affected product, with remediation in version 147.0.7727.101. The vendor field indicates Apple with medium confidence based on NVD CPE data; this appears to reflect macOS as an affected platform rather than the vulnerability origin. The Chrome Release Notes confirm the fix date and severity classification.

Official resources

2026-04-15