PT-2026-33145 · Google+1 · Google Chrome+1

CVE-2026-6307

·

Published

2026-03-29

·

Updated

2026-08-31

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 147.0.7727.101
Description A type confusion issue exists in the Turbofan JIT compiler within the V8 engine. This flaw occurs during CSE/GVN FrameState merging and JS-to-Wasm deoptimization. A remote attacker can exploit this by inducing the browser to load a specially crafted HTML page, allowing the execution of arbitrary code inside a sandbox. The issue enables arbitrary renderer read/write capabilities and a V8 sandbox escape.
Recommendations Update Google Chrome to version 147.0.7727.101 or later.

Exploit

Fix

DoS

RCE

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05527
CVE-2026-6307
OPENSUSE-SU-2026:10572-1
OPENSUSE-SU-2026:20588-1
OPENSUSE-SU-2026:20660-1

Affected Products

Google Chrome
Red Os