CVE-2026-6297Use After Free in Google Chrome

Severity
8.3HIGHNVD
EPSS
0.0%
top 99.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 15
Latest updateApr 16

Description

Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.6 | Impact: 6.0

Affected Packages1 packages

CVEListV5google/chrome147.0.7727.101147.0.7727.101

🔴Vulnerability Details

3
VulDB
Google Chrome up to 147.0.7727.55 Proxy use after free (ID 493628)2026-04-16
CVEList
CVE-2026-6297: Use after free in Proxy in Google Chrome prior to 1472026-04-15
GHSA
GHSA-pfc6-jxgq-cf62: Use after free in Proxy in Google Chrome prior to 1472026-04-15

📋Vendor Advisories

2
Red Hat
chromium-browser: Use after free in Proxy2026-04-15
Chrome
Stable Channel Update for Desktop: CVE-2026-62962026-04-15

💬Community

3
Bugzilla
CVE-2026-6296 CVE-2026-6297 CVE-2026-6298 CVE-2026-6300 CVE-2026-6301 CVE-2026-6302 CVE-2026-6305 CVE-2026-6306 CVE-2026-6307 CVE-2026-6318 CVE-2026-6319 CVE-2026-6358 CVE-2026-6359 CVE-2026-6360 CVE-2026-04-15
Bugzilla
CVE-2026-6296 CVE-2026-6297 CVE-2026-6298 CVE-2026-6300 CVE-2026-6301 CVE-2026-6302 CVE-2026-6305 CVE-2026-6306 CVE-2026-6307 CVE-2026-6318 CVE-2026-6319 CVE-2026-6358 CVE-2026-6359 CVE-2026-6360 CVE-2026-04-15
Bugzilla
CVE-2026-6297 chromium-browser: Use after free in Proxy2026-04-15
CVE-2026-6297 — Use After Free in Google Chrome | cvebase