PT-2026-33145 · Google+1 · Google Chrome+1
CVE-2026-6307
·
Published
2026-03-29
·
Updated
2026-08-31
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 147.0.7727.101
Description
A type confusion issue exists in the Turbofan JIT compiler within the V8 engine. This flaw occurs during CSE/GVN FrameState merging and JS-to-Wasm deoptimization. A remote attacker can exploit this by inducing the browser to load a specially crafted HTML page, allowing the execution of arbitrary code inside a sandbox. The issue enables arbitrary renderer read/write capabilities and a V8 sandbox escape.
Recommendations
Update Google Chrome to version 147.0.7727.101 or later.
Exploit
Fix
DoS
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Red Os