CVE-2026-6309Use After Free in Google Chrome

Severity
8.3HIGHNVD
EPSS
0.0%
top 94.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 15
Latest updateApr 16

Description

Use after free in Viz in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.6 | Impact: 6.0

Affected Packages1 packages

CVEListV5google/chrome147.0.7727.101147.0.7727.101

🔴Vulnerability Details

3
VulDB
Google Chrome up to 147.0.7727.55 Viz use after free (ID 497846)2026-04-16
CVEList
CVE-2026-6309: Use after free in Viz in Google Chrome prior to 1472026-04-15
GHSA
GHSA-vm22-5c7q-8w8h: Use after free in Viz in Google Chrome prior to 1472026-04-15

📋Vendor Advisories

2
Chrome
Stable Channel Update for Desktop: CVE-2026-63092026-04-15
Red Hat
chromium-browser: Use after free in Viz2026-04-15

💬Community

1
Bugzilla
CVE-2026-6309 Google Chrome: Viz: Google Chrome: Sandbox escape in Viz component via use-after-free vulnerability2026-04-15
CVE-2026-6309 — Use After Free in Google Chrome | cvebase