PatchSiren cyber security CVE debrief
CVE-2026-6919 Google CVE debrief
A use-after-free vulnerability in Google Chrome's DevTools component allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. The vulnerability exists in Chrome versions prior to 147.0.7727.117 and was assigned a High severity by Chromium security. The CVSS 3.1 score of 9.6 reflects network attack vector, low attack complexity, no privileges required, user interaction required, and changed scope with high impact to confidentiality, integrity, and availability. The use-after-free weakness (CWE-416) in DevTools can be triggered via a crafted HTML page, enabling further privilege escalation from renderer compromise to sandbox escape.
- Vendor
- Product
- Chrome
- CVSS
- CRITICAL 9.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-23
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-04-23
- Advisory updated
- 2026-05-26
Who should care
Organizations with Chrome deployments, particularly those where users may access untrusted web content; security teams monitoring for browser-based attack chains; developers and security researchers using Chrome DevTools; enterprises with bring-your-own-device policies where Chrome updates may lag.
Technical summary
The vulnerability is a use-after-free (CWE-416) in Chrome's DevTools implementation. An attacker who has achieved code execution in the renderer process—Chrome's sandboxed context for web content—can trigger this memory safety bug to escape the sandbox and gain higher privileges. The attack requires user interaction to load a crafted HTML page. The fix was released in Chrome 147.0.7727.117. The high CVSS score (9.6) stems from the potential for complete system compromise following initial renderer compromise, with changed scope indicating impact beyond the vulnerable component.
Defensive priority
critical
Recommended defensive actions
- Update Google Chrome to version 147.0.7727.117 or later immediately
- Verify Chrome version across all endpoints using enterprise management tools
- Review browser isolation policies to limit impact of renderer compromises
- Monitor for suspicious HTML page delivery attempts targeting development or debugging workflows
- Apply security updates for Chrome on all platforms including Windows, macOS, and Linux
- Consider enabling site isolation and enhanced security settings as defense-in-depth
- Audit for unauthorized DevTools usage or debugging sessions in enterprise environments
Evidence notes
CVE published 2026-04-23; NVD record modified 2026-05-26. Vendor advisory confirms fix in Chrome 147.0.7727.117. Chromium issue tracker reference indicates permissions-required access for full technical details. CPE configurations confirm affected product as Google Chrome with version bound prior to 147.0.7727.116.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6919 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6919
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6919 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6919
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_22.html
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/493652473
[email protected] - Permissions Required, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.