Junglewise Threat Intelligence

CVE-2026-6297: Google Chrome use after free in Proxy

CVE-2026-6297 · Severity: high · CVSS 8.3 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability was identified in the Google Chrome web browser's proxy component. An attacker could use a specially crafted webpage to bypass the browser's security 'sandbox,' which is designed to keep malicious code from affecting the rest of the computer. If successfully exploited, this could allow an attacker to gain unauthorized access to the underlying operating system and sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Proxy component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during proxy-related operations, allowing an attacker in a privileged network position to exploit the memory corruption via a crafted HTML page. Successful exploitation requires user interaction (visiting a malicious site) and can lead to a sandbox escape, allowing the attacker to execute arbitrary code outside of the browser's restricted environment. This issue was addressed in Chrome version 147.0.7727.101.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-17: other: Vulnerability reported to vendor by researcher heapracer
  • 2026-04-15: patched: Fixed in Chrome Stable channel update 147.0.7727.101
  • 2026-04-15: disclosed: Public advisory published

References