
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6304 is a use-after-free vulnerability in the Graphite rendering engine component of Google Chrome and Chromium-based browsers. It was reported internally by Google on March 26, 2026, and publicly disclosed on April 15, 2026, as part of a stable channel update. The vulnerability affects Google Chrome versions prior to 147.0.7727.101 and Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.3 (High) (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), arising from improper memory management in Chrome's Graphite text rendering engine. Exploitation requires that an attacker has already compromised the browser's renderer process; from that position, a crafted HTML page can trigger the use-after-free condition to achieve a sandbox escape. The attack vector is network-based, requires user interaction (visiting a malicious page), and has high attack complexity, reflecting the prerequisite of renderer compromise. The Chromium issue tracker entry is available at https://issues.chromium.org/issues/496393742 (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a remote attacker who has already compromised the renderer process to escape Chrome's sandbox and potentially execute arbitrary code on the underlying host system. This impacts confidentiality, integrity, and availability at a HIGH level, meaning an attacker could access sensitive data, modify system state, or disrupt availability of the affected system. The scope change (S:C in CVSS) reflects that exploitation can affect resources beyond the browser's security boundary, enabling full system compromise (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.022–0.045%, placing it in a low percentile for near-term exploitation likelihood (GitHub Advisory). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a two-stage attack: first compromising the renderer process (e.g., via a separate vulnerability), then leveraging CVE-2026-6304 for sandbox escape, which raises the practical bar for attackers.
chrome.exe or chromium (e.g., cmd.exe, powershell.exe, /bin/sh, curl, wget) that are not typical browser subprocesses.Google has released a patch in Chrome version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac); users should update immediately (Chrome Release). Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory (Microsoft MSRC). Enable automatic browser updates to ensure timely patching. As a behavioral mitigation, avoid visiting untrusted or suspicious websites, and consider deploying web content filtering or browser isolation solutions to reduce exposure.
The CIS issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-6304, could allow for arbitrary code execution, urging prompt updates. F5 Labs included this CVE in their weekly threat bulletin for April 22, 2026. Kaspersky also catalogued the vulnerability in their threat database. Coverage appeared across security news outlets including CyberPress and TechLomedia, highlighting the broader batch of 31 fixes in the Chrome 147 update. Community discussion on social platforms (Bluesky, Nitter) was moderate, consistent with a high-severity but non-actively-exploited browser vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."