CVE-2026-6296 is a critical heap buffer overflow vulnerability in the ANGLE graphics library component of Google Chrome versions prior to 147.0.7727.101. This memory corruption flaw could allow a remote attacker to escape the Chrome sandbox through a maliciously crafted HTML page, potentially leading to complete system compromise. The vulnerability carries a CVSS score of 9.6 (Critical) with a network-based attack vector requiring minimal complexity and only user interaction (clicking a malicious link). The attack can bypass sandbox protections and result in high impact to confidentiality, integrity, and availability. Google has rated this as Critical severity. While there are no public indicators of active exploitation or available proof-of-concept code at this time, the vulnerability remains a significant concern given its critical nature and the ease of delivery through web-based attacks. Organizations should prioritize patching Chrome to version 147.0.7727.101 or later as soon as possible, particularly for users in high-risk environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.