CVE-2026-6310 is a use-after-free vulnerability in Google Chrome's Dawn graphics library affecting versions prior to 147.0.7727.101. This flaw allows a remote attacker who has already compromised the renderer process to potentially escape the sandbox and gain unauthorized system access through a crafted HTML page. The vulnerability carries a Chromium security severity rating of High. The attack requires network access and user interaction, with high attack complexity, but poses significant risk across confidentiality, integrity, and availability. The CVSS score of 8.3 reflects the serious potential impact, though successful exploitation requires the attacker to have already achieved renderer process compromise as a prerequisite. The high CVSS rating indicates this is a critical privilege escalation vector for attackers seeking to break out of Chrome's security sandbox. There is currently no evidence of active exploitation in the wild, as indicated by the vulnerability's absence from CISA's Known Exploited Vulnerabilities catalog and its inactive Hot List status. The EPSS score of 0.00039 suggests this vulnerability ranks lower in likelihood of exploitation compared to most disclosed CVEs. However, the vulnerability should still be prioritized for patching given its high severity rating and the theoretical risk it poses in multi-stage attack scenarios.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.