
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6310 is a use-after-free vulnerability in Dawn, the WebGPU graphics component of Google Chrome, that allows a remote attacker who has already compromised the renderer process to potentially perform a sandbox escape via a specially crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.101 and Microsoft Edge (Chromium-based). The vulnerability was reported by Google on March 31, 2026, and publicly disclosed on April 15, 2026, alongside a patch. It carries a CVSS v3.1 base score of 8.3 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference), rooted in improper memory management within Chrome's Dawn graphics subsystem — the browser's WebGPU implementation. An attacker who has already achieved renderer process compromise can trigger the use-after-free condition by directing a victim to a crafted HTML page, causing the browser to reference freed memory in the Dawn component and potentially execute arbitrary code outside the sandbox. Exploitation requires high attack complexity (a pre-compromised renderer) and user interaction (visiting a malicious page), making it a second-stage exploit typically chained with a separate renderer compromise (Chrome Releases, GitHub Advisory, Red Hat Bugzilla).
Successful exploitation allows a remote attacker to escape Chrome's sandbox, leading to high impact on confidentiality, integrity, and availability of the affected system. An attacker who chains this vulnerability with a renderer exploit could achieve arbitrary code execution at the OS level, potentially enabling full system compromise, data exfiltration, installation of malware, or lateral movement within a network. The scope change (S:C in CVSS) reflects that exploitation can affect resources beyond the browser's security boundary (GitHub Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.022–0.042%, placing it in a low-to-moderate exploitation probability range. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a pre-existing renderer compromise, raising the bar for attackers and limiting the practical exploitability to sophisticated, multi-stage attack chains (GitHub Advisory).
Google has released a patch in Chrome version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac), which addresses this vulnerability along with 30 other security fixes. Microsoft has also issued a corresponding update for Edge (Chromium-based). Organizations should update all Chrome and Edge deployments to the patched versions immediately. No configuration-based workarounds are available; updating is the only remediation (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome security update addressing 31 issues, which received coverage from security outlets including CyberPress, TechLomedia, and BeyondMachines, with commentary noting the significance of multiple sandbox escape-capable flaws in a single release. CIS issued an advisory noting that multiple vulnerabilities in this Chrome update could allow arbitrary code execution. F5 Labs included it in their weekly threat bulletin for April 22, 2026. Community reaction was moderate, with automated CVE tracking accounts on Bluesky and Nitter flagging the disclosure shortly after publication (Chrome Releases, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."