
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6311 is a high-severity "Uninitialized Use in Accessibility" vulnerability in Google Chrome on Windows. It affects all Chrome versions prior to 147.0.7727.101 and was reported internally by Google on March 31, 2026, with a patch released on April 15, 2026. The vulnerability carries a CVSS v3.1 base score of 8.3 (High) (Chrome Release, GitHub Advisory). Microsoft Edge (Chromium-based) is also listed as an affected product (Microsoft MSRC).
The vulnerability is rooted in the use of uninitialized memory within Chrome's accessibility subsystem on Windows, classified under CWE-457 (Use of Uninitialized Variable) and CWE-824 (Access of Uninitialized Pointer) (GitHub Advisory). Exploitation requires that an attacker has already compromised the renderer process — a significant precondition — and then leverages the uninitialized memory condition via a crafted HTML page to escape the Chrome sandbox. The attack vector is network-based, requires user interaction (e.g., visiting a malicious page), and has high attack complexity due to the renderer compromise prerequisite. The underlying Chromium issue is tracked at https://issues.chromium.org/issues/498201025, though access may be restricted pending broad patch deployment (Chrome Release).
Successful exploitation allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox, potentially achieving arbitrary code execution with elevated privileges on the underlying Windows system. This results in high impact to confidentiality, integrity, and availability — an attacker could access sensitive user data, modify system files, or disrupt system operation (GitHub Advisory). The scope change (S:C in CVSS) reflects that exploitation can affect resources beyond the browser's security boundary, enabling lateral movement or persistence on the host system (Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.023% (0.000230), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement that the renderer process must already be compromised, making chained exploitation (e.g., combining with a separate renderer bug) the realistic attack scenario.
chrome.exe or the Chrome GPU/renderer process (e.g., cmd.exe, powershell.exe, curl.exe) that are not typical browser subprocesses.chrome.exe or a Chrome subprocess as the parent of unexpected executables.%APPDATA%, %TEMP%) created by Chrome processes, including dropped scripts, executables, or scheduled task definitions.accessibility.dll or related modules) indicating abnormal memory access patterns.Google has released a fix in Chrome version 147.0.7727.101 (Windows/Linux) and 147.0.7727.102 (Mac), distributed via the stable channel update on April 15, 2026 (Chrome Release). Organizations should immediately update all Chrome installations to version 147.0.7727.101 or later and enforce automatic updates across managed endpoints. As a defense-in-depth measure, consider enabling Chrome's Site Isolation feature and restricting access to untrusted websites via web filtering policies until patching is confirmed across all systems. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update (Microsoft MSRC).
The vulnerability was part of a large Chrome stable channel update addressing 31 security issues, which drew coverage from security news outlets including CyberPress and TechLomedia, noting the breadth of critical and high-severity fixes (Feedly). CIS issued an advisory noting that multiple Chrome vulnerabilities in this release could allow arbitrary code execution (CIS Advisory). F5 Labs included this CVE in their weekly threat bulletin for April 22, 2026. Community reaction on social platforms was moderate, consistent with a high-severity but non-zero-day Chrome patch cycle.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."