PatchSiren cyber security CVE debrief
CVE-2026-6309 Google CVE debrief
A use-after-free vulnerability in Google Chrome's Viz compositor (CVE-2026-6309) enables sandbox escape from a compromised renderer process. The flaw was patched in Chrome 147.0.7727.101, released April 15, 2026. No known exploitation in the wild has been confirmed, and the vulnerability is not listed in CISA KEV.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-15
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-04-15
- Advisory updated
- 2026-05-26
Who should care
Organizations with unmanaged or broadly deployed Chrome installations; security teams defending against advanced persistent threats employing browser exploitation chains; endpoint protection teams monitoring for sandbox escape indicators
Technical summary
CVE-2026-6309 is a use-after-free vulnerability in the Viz compositor component of Google Chrome. The flaw exists in versions prior to 147.0.7727.101. An attacker who has already compromised the renderer process can exploit this vulnerability to escape the Chrome sandbox. The attack requires a crafted HTML page and user interaction. The vulnerability is classified as High severity by Chromium security standards with a CVSS 3.1 score of 8.3. The underlying weakness is CWE-416 (Use After Free).
Defensive priority
HIGH
Recommended defensive actions
- Update Google Chrome to version 147.0.7727.101 or later across all endpoints
- Prioritize patching for systems where users browse untrusted or adversarial web content
- Consider enabling site isolation and enhanced site isolation policies as defense-in-depth
- Monitor for unusual renderer process crashes or unexpected sandbox escape attempts in Chrome logs
- Review and restrict browser extensions to reduce renderer compromise attack surface
Evidence notes
The CVE description and NVD record confirm this is a use-after-free (CWE-416) in Chrome's Viz component. The vendor advisory from Google Chrome Releases establishes the fixed version as 147.0.7727.101. The Chromium issue tracker reference indicates restricted access (Permissions Required). CVSS 3.1 score of 8.3 reflects network attack vector with high complexity, requiring user interaction, with scope change and high impact across confidentiality, integrity, and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6309 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6309
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6309 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6309
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/497846428
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.