Google Chrome disclosed two high-severity CWE-416 use-after-free vulnerabilities affecting versions prior to 147.0.7727.101, including CVE-2026-6299 in the Prerender component and CVE-2026-6309 in Viz. The Prerender flaw is rated critical and could let a remote attacker achieve arbitrary code execution if a user opens a crafted HTML page, with a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
The Viz vulnerability could allow a remote attacker, after compromising the renderer process, to potentially escape Chrome’s sandbox through a crafted HTML page. Google classified the Viz issue as high severity and assigned it a CVSS v3.1 vector of AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H, indicating significant impact despite higher attack complexity. Both issues were published in CVE records on April 15, 2026, and users running Chrome versions earlier than 147.0.7727.101 are affected.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Later the same day, the CVE records for both Chrome vulnerabilities were updated with CVSS v3.1 vectors. The updates clarified the severity and impact of the Prerender arbitrary code execution flaw and the Viz sandbox-escape issue.
A high-severity use-after-free vulnerability in Google Chrome's Viz component was recorded as CVE-2026-6309. The issue affects Chrome versions prior to 147.0.7727.101 and could enable sandbox escape after renderer compromise through a crafted HTML page.
A critical use-after-free vulnerability in Google Chrome's Prerender component was recorded as CVE-2026-6299. The flaw affects Chrome versions prior to 147.0.7727.101 and could allow remote code execution via a crafted HTML page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.