Junglewise Threat Intelligence

CVE-2026-6301: Google Chrome type confusion in Turbofan

CVE-2026-6301 · Severity: high · CVSS 8.8 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Turbofan component, which is responsible for optimizing JavaScript performance. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While the code is initially confined to a 'sandbox' (a restricted area of the browser), this flaw represents a significant step in a potential multi-stage attack to compromise the entire system.

Technical details

A type confusion vulnerability (CWE-843) exists in the Turbofan optimization engine of the V8 JavaScript engine in Google Chrome. The flaw occurs when the engine incorrectly handles object types during JIT (Just-In-Time) compilation, allowing for memory corruption. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and inducing a user to visit it. Successful exploitation allows for arbitrary code execution within the browser's sandbox environment. The issue is resolved in Chrome version 147.0.7727.101 and later.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-23: other: Reported by security researcher qymag1c
  • 2026-04-15: patched: Fixed in version 147.0.7727.101/102
  • 2026-04-15: disclosed

References