CVE-2026-6304
vulnerability analysis and mitigation

Overview

CVE-2026-6304 is a use-after-free vulnerability in the Graphite rendering engine component of Google Chrome and Chromium-based browsers. It was reported internally by Google on March 26, 2026, and publicly disclosed on April 15, 2026, as part of a stable channel update. The vulnerability affects Google Chrome versions prior to 147.0.7727.101 and Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.3 (High) (Chrome Release, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), arising from improper memory management in Chrome's Graphite text rendering engine. Exploitation requires that an attacker has already compromised the browser's renderer process; from that position, a crafted HTML page can trigger the use-after-free condition to achieve a sandbox escape. The attack vector is network-based, requires user interaction (visiting a malicious page), and has high attack complexity, reflecting the prerequisite of renderer compromise. The Chromium issue tracker entry is available at https://issues.chromium.org/issues/496393742 (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation allows a remote attacker who has already compromised the renderer process to escape Chrome's sandbox and potentially execute arbitrary code on the underlying host system. This impacts confidentiality, integrity, and availability at a HIGH level, meaning an attacker could access sensitive data, modify system state, or disrupt availability of the affected system. The scope change (S:C in CVSS) reflects that exploitation can affect resources beyond the browser's security boundary, enabling full system compromise (GitHub Advisory, Feedly).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.022–0.045%, placing it in a low percentile for near-term exploitation likelihood (GitHub Advisory). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a two-stage attack: first compromising the renderer process (e.g., via a separate vulnerability), then leveraging CVE-2026-6304 for sandbox escape, which raises the practical bar for attackers.

Exploitation steps

  1. Renderer Compromise: Exploit a separate vulnerability (e.g., a V8 or Blink bug) to gain code execution within Chrome's renderer process, which operates in a sandboxed environment.
  2. Craft Malicious HTML: Prepare a crafted HTML page that triggers the use-after-free condition in Chrome's Graphite text rendering engine by manipulating font or text rendering objects in a way that causes memory to be freed and then referenced.
  3. Deliver Payload: Host the malicious page on an attacker-controlled server and entice the target user to visit it (e.g., via phishing, malvertising, or a compromised website).
  4. Trigger UAF: When the victim's browser renders the page, the Graphite engine dereferences freed memory, allowing the attacker to control execution flow within the renderer.
  5. Sandbox Escape: Leverage the memory corruption to break out of the Chrome sandbox, gaining code execution at the OS level with the privileges of the browser process (Chrome Release, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser process to unknown external IPs following visits to unfamiliar or suspicious websites; unusual DNS lookups initiated by the Chrome process.
  • Process: Unexpected child processes spawned by chrome.exe or chromium (e.g., cmd.exe, powershell.exe, /bin/sh, curl, wget) that are not typical browser subprocesses.
  • Logs: Browser crash reports or renderer process termination logs coinciding with visits to specific URLs; Windows Event Logs or Linux syslog entries showing abnormal process creation from the browser.
  • File System: Unexpected files written to user profile directories or temp folders by the browser process; new scheduled tasks or cron jobs created under the browser's user account.

Mitigation and workarounds

Google has released a patch in Chrome version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac); users should update immediately (Chrome Release). Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory (Microsoft MSRC). Enable automatic browser updates to ensure timely patching. As a behavioral mitigation, avoid visiting untrusted or suspicious websites, and consider deploying web content filtering or browser isolation solutions to reduce exposure.

Community reactions

The CIS issued an advisory noting that multiple vulnerabilities in Google Chrome, including CVE-2026-6304, could allow for arbitrary code execution, urging prompt updates. F5 Labs included this CVE in their weekly threat bulletin for April 22, 2026. Kaspersky also catalogued the vulnerability in their threat database. Coverage appeared across security news outlets including CyberPress and TechLomedia, highlighting the broader batch of 31 fixes in the Chrome 147 update. Community discussion on social platforms (Bluesky, Nitter) was moderate, consistent with a high-severity but non-actively-exploited browser vulnerability.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management