PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6304 Google CVE debrief

A use-after-free vulnerability in the Graphite font rendering library within Google Chrome enables sandbox escape from a compromised renderer process. The flaw was addressed in Chrome 147.0.7727.101, released April 2026. The CVSS 3.1 score of 8.3 reflects high impact across confidentiality, integrity, and availability, with attack complexity rated as high due to the prerequisite renderer compromise. No known exploitation in ransomware campaigns has been documented.

Vendor
Google
Product
Chrome
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-15
Original CVE updated
2026-05-26
Advisory published
2026-04-15
Advisory updated
2026-05-26

Who should care

Organizations with managed Chrome deployments, security teams responsible for browser security posture, and incident responders tracking renderer exploitation chains

Technical summary

The vulnerability exists in Chrome's integration of the Graphite font rendering library, where a use-after-free condition can be triggered through crafted HTML content. Successful exploitation requires prior compromise of the renderer process, after which the memory corruption flaw may allow escape from Chrome's sandbox security boundary. The fix was included in the stable channel update released April 15, 2026.

Defensive priority

high

Recommended defensive actions

  • Upgrade Google Chrome to version 147.0.7727.101 or later across all managed endpoints
  • Verify automatic update mechanisms are functional for Chrome installations
  • Review browser isolation policies to limit renderer process compromise impact
  • Monitor for anomalous renderer crashes or unexpected sandbox escape attempts
  • Audit endpoints for Chrome versions prior to 147.0.7727.101
  • resourceLinkAnnotations:ref-4

Evidence notes

The CVE description and NVD record identify Google Chrome as the affected product, with remediation in version 147.0.7727.101. The vendor field indicates Apple with medium confidence based on NVD CPE data; this appears to reflect macOS as an affected platform rather than the vulnerability origin. The Chrome Release Notes confirm the fix date and severity classification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6304 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6304

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6304 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6304

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.