Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6296

33
FAUCET Score

CVE-2026-6296 is a critical heap buffer overflow vulnerability in the ANGLE graphics library component of Google Chrome versions prior to 147.0.7727.101. This memory corruption flaw could allow a remote attacker to escape the Chrome sandbox through a maliciously crafted HTML page, potentially leading to complete system compromise. The vulnerability carries a CVSS score of 9.6 (Critical) with a network-based attack vector requiring minimal complexity and only user interaction (clicking a malicious link). The attack can bypass sandbox protections and result in high impact to confidentiality, integrity, and availability. Google has rated this as Critical severity. While there are no public indicators of active exploitation or available proof-of-concept code at this time, the vulnerability remains a significant concern given its critical nature and the ease of delivery through web-based attacks. Organizations should prioritize patching Chrome to version 147.0.7727.101 or later as soon as possible, particularly for users in high-risk environments.

Impacted Technologies

VendorProductVersion(s)CPE
>= 147.0.7727.101, < 147.0.7727.101CPE match
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
< 147.0.7727.101CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.6CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 30th percentile among its peer group of 836 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Microsoft Edge (Chromium-based)Fixed in: 147.0.3912.72
googlevendor investigatingvia chrome_releases
View patch

Vendor Advisories (2)

microsoft2026-Apr/CVE-2026-6296

Chromium: CVE-2026-6296 Heap buffer overflow in ANGLE

Apr 14, 2026
googlegoogle:chrome-7d655429efb624cbCRITICAL

Stable Channel Update for ChromeOS / ChromeOS Flex

References

chromereleases.googleblog.com / 2026/04/stable-channel-update-for-desktop_15.html
Release NotesVendor Advisory
issues.chromium.org / issues/490170083
Permissions Required