CVE-2026-6314Out-of-bounds Write in Google Chrome

Severity
8.3HIGHNVD
EPSS
0.0%
top 94.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 15
Latest updateApr 16

Description

Out of bounds write in GPU in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.6 | Impact: 6.0

Affected Packages1 packages

CVEListV5google/chrome147.0.7727.101147.0.7727.101

🔴Vulnerability Details

3
VulDB
Google Chrome up to 147.0.7727.55 GPU out-of-bounds write (ID 498782)2026-04-16
GHSA
GHSA-q4f4-mqcx-4prx: Out of bounds write in GPU in Google Chrome prior to 1472026-04-15
CVEList
CVE-2026-6314: Out of bounds write in GPU in Google Chrome prior to 1472026-04-15

📋Vendor Advisories

2
Red Hat
chromium-browser: Out of bounds write in GPU2026-04-15
Chrome
Stable Channel Update for Desktop: CVE-2026-63142026-04-15

💬Community

1
Bugzilla
CVE-2026-6314 Google Chrome: Chromium: Google Chrome and Chromium: Sandbox escape via out-of-bounds write in GPU2026-04-15
CVE-2026-6314 — Out-of-bounds Write in Google Chrome | cvebase