Junglewise Threat Intelligence

CVE-2026-6300: Google Chrome use after free in CSS

CVE-2026-6300 · Severity: high · CVSS 8.8 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome web browser's CSS engine. By tricking a user into visiting a specially crafted website, a remote attacker could execute malicious code on the user's computer. While this code is restricted by the browser's security sandbox, it still represents a significant risk to the integrity of the application and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the CSS engine of Google Chrome prior to version 147.0.7727.101. The flaw is triggered when the browser incorrectly manages memory for CSS objects, allowing an attacker to reuse memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the browser's sandbox environment. The vulnerability is tracked as CWE-416 and has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-12: other: Vulnerability reported to Chrome by researcher c6eed09fc8b174b0f3eebedcceb1e792
  • 2026-04-15: patched: Fixed in Chrome version 147.0.7727.101/102
  • 2026-04-15: disclosed: Public advisory published by Google Chrome team

References