Junglewise Threat Intelligence

CVE-2026-6316: Google Chrome use after free in Forms

CVE-2026-6316 · Severity: high · CVSS 8.8 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's web form handling component. By tricking a user into visiting a specially crafted website, a remote attacker could execute malicious code on the user's computer. While this code is restricted by Chrome's security sandbox, it could still lead to data theft or be used as part of a larger attack to compromise the entire system.

Technical details

A use-after-free (UAF) vulnerability exists in the Forms component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of web forms, allowing an attacker to reference memory after it has been freed. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chrome renderer sandbox. The vulnerability is addressed in Google Chrome version 147.0.7727.101 and later.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-04-03: other: Reported to Google
  • 2026-04-15: disclosed: Initial disclosure and NVD publication
  • 2026-04-15: patched: Fixed in version 147.0.7727.101/102

References