CVE-2026-6301 is a type confusion vulnerability in Google Chrome's Turbofan JavaScript engine that affects versions prior to 147.0.7727.101. This flaw allows remote attackers to execute arbitrary code within the browser sandbox by tricking users into viewing malicious HTML pages. The vulnerability has a High security rating from Chromium's assessment team. The vulnerability presents a significant attack surface with a CVSS score of 8.8 (High), requiring only network access and user interaction to exploit, with no special privileges needed. Successful exploitation could result in complete compromise of confidentiality, integrity, and availability of the affected system, though the impact is contained within the sandbox environment. Exploitation status indicates the vulnerability is currently inactive on threat tracking lists and has not been designated for the Known Exploited Vulnerabilities (KEV) catalog. The EPSS score of 0.00036 suggests minimal real-world exploitation likelihood relative to other vulnerabilities, and no public exploit code availability has been reported. Organizations should prioritize patching to Chrome 147.0.7727.101 or later as part of standard update procedures rather than emergency response measures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.