CVE-2026-6314 is an out-of-bounds write vulnerability in the GPU process of Google Chrome versions prior to 147.0.7727.101. This memory safety flaw could allow an attacker who has already compromised the GPU process to escape the sandbox and gain elevated system access by crafting a malicious HTML page. The vulnerability carries a CVSS score of 8.3 (HIGH) and requires network access with moderately high attack complexity, user interaction, and prior GPU process compromise. The attack can result in complete confidentiality, integrity, and availability breaches with scope change, representing significant risk to affected systems. Chromium has classified this as a High severity issue. There is currently no evidence of active exploitation in the wild, and the vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. However, the moderate FAUCET Risk Score of 50/100 warrants timely patching. Organizations should prioritize upgrading to Chrome version 147.0.7727.101 or later to mitigate this sandbox escape vector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 147.0.7727.101, < 147.0.7727.101CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 147.0.7727.101CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.