Junglewise Threat Intelligence

CVE-2026-6311: Google Chrome uninitialized use in Accessibility sandbox escape

CVE-2026-6311 · Severity: high · CVSS 8.3 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's accessibility features on Windows could allow an attacker to bypass the browser's security sandbox. To exploit this, an attacker would first need to compromise the browser's rendering process, typically by tricking a user into visiting a malicious website. If successful, the attacker could gain broader access to the underlying Windows operating system, potentially leading to unauthorized data access or full system compromise.

Technical details

This vulnerability (CWE-457) involves the use of uninitialized memory within the Accessibility component of Google Chrome on Windows. The flaw allows a remote attacker who has already achieved code execution within the sandboxed renderer process to perform a sandbox escape. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this uninitialized state to execute arbitrary code with the privileges of the browser's parent process. The issue is resolved in Google Chrome version 147.0.7727.101 for Windows.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-31: disclosed: Reported by Google internal researchers
  • 2026-04-15: patched: Fixed in version 147.0.7727.101/102
  • 2026-04-15: advisory

References