CVE-2026-6310
published 2026-04-15CVE-2026-6310: Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a…
high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 147.0.7727.101 | 147.0.7727.101 | |
| chrome | >= 147.0.7727.101 < 147.0.7727.101 | 147.0.7727.101 | |
| chrome_chrome | — | — |
Chrome
Stable Channel Update for Desktop: CVE-2026-6309
vendor_chrome·2026-04-15·CVSS 8.3
CVE-2026-6309 [HIGH] Stable Channel Update for Desktop: CVE-2026-6309
Stable Channel Update for Desktop
CVE-2026-6309: Use after free in Viz. Reported by Google on 2026-03-30 [TBD][ 497880137 ] High CVE-2026-6360: Use after free in FileSystem
Reported by asjidkalam on 2026-03-31 [N/A][ 497969820 ] High CVE-2026-6310: Use after free in Dawn
Severity: high
Red Hat
chromium-browser: Use after free in Dawn
vendor_redhat·2026-04-15·CVSS 8.3
CVE-2026-6310 [HIGH] CWE-825 chromium-browser: Use after free in Dawn
chromium-browser: Use after free in Dawn
An use after free flaw was found in the Dawn component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=497969820
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
VulDB
Google Chrome up to 147.0.7727.55 Dawn use after free (ID 497969)
vuldb·2026-04-16·CVSS 8.3
CVE-2026-6310 [HIGH] Google Chrome up to 147.0.7727.55 Dawn use after free (ID 497969)
A vulnerability, which was classified as critical, was found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Dawn. The manipulation results in use after free.
This vulnerability is identified as CVE-2026-6310. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
GHSA-xhc9-2rpq-wh58: Use after free in Dawn in Google Chrome prior to 147
ghsa_unreviewed·2026-04-15
CVE-2026-6310 [HIGH] CWE-416 GHSA-xhc9-2rpq-wh58: Use after free in Dawn in Google Chrome prior to 147
Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-
bugzilla·2026-04-17·CVSS 8.8
CVE-2026-6299 [HIGH] CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-
CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-2026-6363 ... chromium: various flaws [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-
bugzilla·2026-04-17·CVSS 8.8
CVE-2026-6299 [HIGH] CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-
CVE-2026-6299 CVE-2026-6303 CVE-2026-6304 CVE-2026-6308 CVE-2026-6309 CVE-2026-6310 CVE-2026-6311 CVE-2026-6312 CVE-2026-6313 CVE-2026-6314 CVE-2026-6315 CVE-2026-6316 CVE-2026-6317 CVE-2026-6361 CVE-2026-6363 ... chromium: various flaws [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-6310 Dawn: Google Chrome: Chromium: Google Chrome: Sandbox escape via use-after-free in Dawn
bugzilla·2026-04-15·CVSS 8.3
CVE-2026-6310 [HIGH] CVE-2026-6310 Dawn: Google Chrome: Chromium: Google Chrome: Sandbox escape via use-after-free in Dawn
CVE-2026-6310 Dawn: Google Chrome: Chromium: Google Chrome: Sandbox escape via use-after-free in Dawn
Use after free in Dawn in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
2026-04-15
Published