PT-2026-33145 · Google · Google Chrome

Published

2026-03-29

·

Updated

2026-05-05

·

CVE-2026-6307

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 147.0.7727.101
Description A type confusion issue exists in the Turbofan JIT compiler, specifically during JS-to-Wasm deoptimization. This allows a remote attacker to execute arbitrary code inside a sandbox by inducing the browser to load a specially crafted HTML page.
Recommendations Update to version 147.0.7727.101 or later.

Fix

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2026-05527
CVE-2026-6307
OPENSUSE-SU-2026:10572-1
OPENSUSE-SU-2026:20588-1

Affected Products

Google Chrome