Google Chrome disclosed two high-severity vulnerabilities in the Turbofan JavaScript optimization engine, tracked as CVE-2026-6301 and CVE-2026-6307. Both flaws are described as type confusion issues (CWE-843) affecting Chrome versions prior to 147.0.7727.101, and both can be triggered by a remote attacker using a crafted HTML page to achieve arbitrary code execution inside the browser sandbox.
The vulnerabilities were assigned the same CVSS v3.1 vector, AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, reflecting network-based exploitation with no privileges required but with user interaction needed. Chromium rated both issues High severity, indicating that organizations running unpatched Chrome versions face meaningful risk from malicious web content and should prioritize upgrading to 147.0.7727.101 or later.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Later on 2026-04-15, the CVE entries for CVE-2026-6301 and CVE-2026-6307 were updated to include CVSS v3.1 vectors of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The updates reflected high impact to confidentiality, integrity, and availability with user interaction required.
On 2026-04-15, Google disclosed two high-severity type confusion vulnerabilities in Chrome's Turbofan JavaScript compiler, tracked as CVE-2026-6301 and CVE-2026-6307. The flaws affect Chrome versions prior to 147.0.7727.101 and could allow remote attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.