Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryrapid-weaponization

Google patches 31 Chrome 147 flaws including critical RCE and sandbox escapes

Updated 11d agoFirst seen Jun 12, 202622 sources

Google released Chrome 147.0.7727.101/.102 for desktop and 147.0.7727.101 for Android to fix a broad set of browser vulnerabilities, with the desktop advisory covering 31 security issues and multiple Critical and High severity bugs. The patched set includes remote code execution and memory-corruption flaws such as CVE-2026-6299 in Prerender, CVE-2026-6297 in Proxy, CVE-2026-6300 in Blink CSS, CVE-2026-6307 and CVE-2026-6363 in V8, CVE-2026-6361 in PDFium, and several use-after-free bugs in Video, Forms, FileSystem, Cast, Permissions, and XR components. Google said Android inherits the same security fixes as the corresponding desktop release unless otherwise noted, and affected versions span Chrome builds prior to 147.0.7727.101 on Linux and Android and prior to 147.0.7727.101/.102 on Windows and macOS.

Several of the flaws could be used in exploit chains to cross Chrome security boundaries, including sandbox escape paths in GPU, Viz, Dawn WebGPU, Accessibility, Graphite, and Proxy components through CVE-2026-6314, CVE-2026-6309, CVE-2026-6310, CVE-2026-6311, CVE-2026-6304, and CVE-2026-6297. Public technical details for many Chromium issues remain restricted while patches propagate, and no confirmed in-the-wild exploitation was cited for these specific April fixes, though multiple reports note Chrome’s recent zero-day activity and the likelihood of rapid weaponization of memory-safety bugs. The Canadian Centre for Cyber Security urged organizations to review Google’s advisory and apply updates promptly, while downstream Chromium-based browsers may remain exposed until they ship their own patched releases.

Share:
Google patches 31 Chrome 147 flaws including critical RCE and sandbox escapes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 15, 20262mo ago

Canada's Cyber Centre issues advisory on Chrome 147 vulnerabilities

On 2026-04-15, the Canadian Centre for Cyber Security published advisory AV26-358 about Google's Chrome desktop security update. The notice identified affected versions prior to 147.0.7727.101/102 on Windows and Mac and prior to 147.0.7727.101 on Linux, and urged users and administrators to apply updates.

Google Chrome security advisory (AV26-358) - Canadian Centre for Cyber Security

Google releases Chrome 147 security updates across desktop and Android

On 2026-04-15, Google released Chrome 147.0.7727.101/.102 for desktop platforms and 147.0.7727.101 for Android. The updates addressed a broad set of vulnerabilities, with multiple references stating the stable-channel release included 31 security fixes affecting components such as Proxy, Prerender, Video, FileSystem, Forms, Cast, Permissions, Viz, Dawn/WebGPU, GPU, XR, PDFium, V8, and Accessibility.

Chrome Releases: Chrome for Android Update
Apr 7, 20263mo ago

Google authors upstream fix for Chrome CSS flaw CVE-2026-6300

On 2026-04-07, Anders Hartvoll Ruud authored commit c34df82 to fix CVE-2026-6300 in Chrome's Blink CSS layout engine. The patch changed iteration logic, added validation helpers, and introduced a regression crashtest.

Google Chrome CVE-2026-6300: Use After Free in CSS Layout Pipeline - Technical Breakdown with Patch Analysis - ZeroPath Blog | ZeroPath
Apr 3, 20263mo ago

Google internally discovers Chrome Permissions flaw CVE-2026-6315

Google discovered and reported CVE-2026-6315 internally on 2026-04-03. The high-severity use-after-free in Chrome's Permissions component primarily affected Android exploitation scenarios.

Quick Look: CVE-2026-6315, Use After Free in Google Chrome Permissions on Android - ZeroPath Blog | ZeroPath
Mar 31, 20263mo ago

Researcher asjidkalam reports Chrome FileSystem flaw CVE-2026-6360

CVE-2026-6360, a high-severity use-after-free in Chrome's FileSystem component, was reported by asjidkalam on 2026-03-31. Google later included the issue among 31 security fixes in its April 2026 stable update.

Google Chrome FileSystem Use After Free (CVE-2026-6360): Brief Summary of a High Severity Browser Flaw - ZeroPath Blog | ZeroPath
Mar 30, 20263mo ago

Google fixes Chrome Prerender flaw CVE-2026-6299 in upstream commit

Google fixed CVE-2026-6299 in commit 8c1ead5a699f53f1915f3187d2bcfac725c46815, authored by Hiroki Nakagawa on 2026-03-30. The bug was a critical use-after-free in Chrome's Prerender feature that could allow remote code execution via crafted HTML.

Google Chrome CVE-2026-6299: Brief Summary of a Critical Use After Free in Prerender - ZeroPath Blog | ZeroPath
Mar 29, 20263mo ago

Project WhatForLunch reports Chrome V8 flaw CVE-2026-6307

CVE-2026-6307, a V8 Turbofan type confusion vulnerability, was reported by Project WhatForLunch on 2026-03-29. Google later shipped fixes for the issue in the April 15, 2026 Chrome 147 security release.

Brief Summary: Google Chrome CVE-2026-6307 Turbofan Type Confusion Enabling Sandboxed Code Execution - ZeroPath Blog | ZeroPath
Mar 24, 20263mo ago

Researcher Syn4pse reports Chrome Video flaw CVE-2026-6302

Google's later April 2026 patch cycle included CVE-2026-6302, a high-severity use-after-free in Chrome's Video component. The vulnerability was explicitly described as having been reported by researcher Syn4pse on 2026-03-24.

Google Chrome CVE-2026-6302: Overview of a High Severity Use After Free in the Video Component - ZeroPath Blog | ZeroPath
Sep 23, 20259mo ago

Google ships another Chrome 140 desktop security update for V8 flaws

On 2025-09-23, Google announced Chrome 140.0.7339.207/.208 for Windows and Mac and 140.0.7339.207 for Linux. The release patched three High-severity V8 issues: CVE-2025-10890, CVE-2025-10891, and CVE-2025-10892.

Chrome Releases: Stable Channel Update for Desktop
Sep 17, 20259mo ago

Google patches four Chrome desktop flaws, including one exploited in the wild

On 2025-09-17, Google released Chrome 140.0.7339.185/.186 for Windows and Mac and 140.0.7339.185 for Linux. The update fixed four High-severity vulnerabilities in V8, Dawn, WebRTC, and ANGLE, and Google said an exploit existed in the wild for CVE-2025-10585.

Chrome Releases: Stable Channel Update for Desktop
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

58 LINKEDOpen in app
Vulnerabilities
37 linked
Use-after-free in Google Chrome Dawn WebGPUInappropriate implementation in V8 in Google ChromeUse-after-free in XR in Google Chrome on AndroidUse-after-free RCE in Google Chrome PrerenderType Confusion in Google Chrome TurbofanSandbox escape use-after-free in Chrome Dawn WebGPUInteger overflow in Google Chrome V8Heap corruption in Google Chrome V8 via crafted HTML pageType Confusion in Google Chrome V8Side-channel information leakage in Google Chrome V8Integer overflow in V8 in Google ChromeUse-after-free in Google Chrome Dawn WebGPUUse-after-free in Google Chrome Visuals sandbox escapeType Confusion in Google Chrome V8Use-after-free in Google Chrome WebRTCHeap buffer overflow in Google Chrome ANGLEUse-after-free in Chrome CSSFontFeatureValuesMapUse-after-free in Dawn in Google ChromeUse-after-free in Dawn in Google ChromeHeap buffer overflow in PDFium in Google ChromeHeap Buffer Overflow in Chrome SkiaSandbox escape via out-of-bounds write in Google Chrome GPUUse-after-free in Google Chrome Permissions on AndroidUse-after-free in Google Chrome CSSUse-after-free in Google Chrome FormsUse-after-free in Google Chrome FileSystemType Confusion in V8 in Google ChromeSandbox escape in Google Chrome Accessibility on WindowsUse-after-free in Google Chrome CastUse-after-free in Google Chrome Video on WindowsSandbox escape use-after-free in Graphite in Google ChromeHeap buffer overflow in ANGLE in Google ChromeOut-of-bounds Read in Google Chrome MediaHeap Buffer Overflow in PDFium in Google ChromeUse-after-free in Google Chrome Proxy sandbox escapeUse-after-free in Google Chrome VideoSandbox escape use-after-free in Google Chrome Viz
Affected products
6 linked
ChromiumOperaBrave BrowserBraveOpera BrowserAndroid
Organizations
15 linked
GoogleBrave SoftwareMicrosoft CorporationOperaVivaldi TechnologiesStatcounterOpera NorwayBleepingComputerTenableSecurityWeekPositive TechnologieseSecurityPlanetThe Hacker WireThe Hacker NewsSC World
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.