CVE-2026-6300 is a use-after-free vulnerability in the CSS rendering engine of Google Chrome versions prior to 147.0.7727.101 that could allow remote attackers to execute arbitrary code within the browser sandbox through a crafted HTML page. The vulnerability carries a CVSS score of 8.8 (High) with a network-based attack vector requiring only user interaction, representing a significant risk to system confidentiality, integrity, and availability. Exploitation is straightforward due to low attack complexity and no privilege requirements, though the attack is contained within the sandbox environment. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows minimal community attention, with an EPSS score of 0.00048 indicating low real-world exploitation probability at this time. Organizations should prioritize updating Chrome to version 147.0.7727.101 or later to mitigate this moderate-to-high risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.