CVE-2026-6297Disclosure(apple / chrome)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 6 mentions (2026-04-16); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline11 mentions / 6d
02356Mentions · 2026-04-15: 1Mentions · 2026-04-16: 6Mentions · 2026-04-21: 1Mentions · 2026-04-23: 1Mentions · 2026-04-30: 1Mentions · 2026-06-07: 1Patch / Workaround · 2026-04-16: 4Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 6Technical Details · 2026-06-07: 104-1504-1604-2104-2304-3006-07
Signal classification3 categories
Disclosure
763.6%
Patch
327.3%
General
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-166
Disclosure4General1Patch1
2026-04-211
Patch1
2026-04-231
Disclosure1
2026-04-301
Patch1
2026-06-071
Disclosure1
Full discourse11 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🌐 CVE‑2026‑6297 – Google Chrome Proxy sandbox escape (High/Critical): In Google Chrome prior to 147.0.7727.101, a use‑after‑free in the Proxy component lets an attacker in a privileged network position trigger object lifetime corruption via a crafted HTML page, enabling sandbox escape and arbitrary code execution in the browser process. CVSS 8.3 (v3.0) but rated “critical” by Google; fixed in Chrome 147.0.7727.101/102 on all desktop platforms, published 2026‑04‑16. https://nvd.nist.gov/vuln/detail/CVE-2026-6297 #CVE20266297 #Chrome #BrowserSecurity #SandboxEscape #RCE

    Post summary

    The text announces CVE-2026-6297, a high‑critical use‑after‑free in Chrome’s proxy sandbox that allows sandbox escape, and it provides vulnerability details and a patch version.

    1001039
    855 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Google #Chrome released LTS-144 version 144.0.7559.249 (Platform Version: 16503.81.0) for ChromeOS devices. This addresses Critical Vulnerability #CVE-2026-6297. Apply Updates! https://chromereleases.googleblog.com/2026/04/long-term-support-channel-update-for_29.html

    Post summary

    Google ChromeOS LTS-144 release includes a patch for CVE-2026-6297, urging users to update their systems.

    00001161
    8.4K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chrome 147で31件の脆弱性を修正、Criticalは5件(CVE-2026-6296、CVE-2026-6297、CVE-2026-6298、CVE-2026-6299、CVE-2026-6358を) https://rocket-boys.co.jp/security-measures-lab/critical-flaws-fixed-in-google-chrome-147-update/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Google released Chrome 147, fixing 31 vulnerabilities—including five critical CVEs—without any mention of PoC, exploits, or active attacks.

    00010107
    381 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🌐 CVE‑2026‑6297 – Google Chrome Proxy sandbox escape (High/Critical): In Google Chrome prior to 147.0.7727.101, a use‑after‑free in the Proxy component lets an attacker in a privileged network position trigger object lifetime corruption via a crafted HTML page, enabling sandbox escape and arbitrary code execution in the browser process. CVSS 8.3 (v3.0) but rated “critical” by Google; fixed in Chrome 147.0.7727.101/102 on all desktop platforms, published 2026‑04‑16. https://nvd.nist.gov/vuln/detail/CVE-2026-6297 #CVE20266297 #Chrome #BrowserSecurity #SandboxEscape #RCE

    Post summary

    A critical use‑after‑free vulnerability (CVE‑2026‑6297) in Google Chrome’s Proxy component has been disclosed, with technical details and a patch available in the latest release.

    1000027
    855 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🌐 CVE‑2026‑6297 – Google Chrome Proxy sandbox escape (High/Critical): In Google Chrome prior to 147.0.7727.101, a use‑after‑free in the Proxy component lets an attacker in a privileged network position trigger object lifetime corruption via a crafted HTML page, enabling sandbox escape and arbitrary code execution in the browser process. CVSS 8.3 (v3.0) but rated “critical” by Google; fixed in Chrome 147.0.7727.101/102 on all desktop platforms, published 2026‑04‑16. https://nvd.nist.gov/vuln/detail/CVE-2026-6297 #CVE20266297 #Chrome #BrowserSecurity #SandboxEscape #RCE

    Post summary

    CVE-2026-6297 is a critical sandbox escape flaw in Google Chrome, now fixed in the latest release; the tweet outlines the vulnerability details and the patch availability.

    100005
    855 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🌐 CVE‑2026‑6297 – Google Chrome Proxy sandbox escape (High/Critical): In Google Chrome prior to 147.0.7727.101, a use‑after‑free in the Proxy component lets an attacker in a privileged network position trigger object lifetime corruption via a crafted HTML page, enabling sandbox escape and arbitrary code execution in the browser process. CVSS 8.3 (v3.0) but rated “critical” by Google; fixed in Chrome 147.0.7727.101/102 on all desktop platforms, published 2026‑04‑16. https://nvd.nist.gov/vuln/detail/CVE-2026-6297 #CVE20266297 #Chrome #BrowserSecurity #SandboxEscape #RCE

    Post summary

    The text announces CVE‑2026‑6297, a critical Chrome sandbox escape vulnerability, outlining its technical details and noting the availability of a patch.

    100005
    855 followersView on X
  • EdKo@EdKolife
    Disclosure

    Researchers just published a paper on an AI agent that found 10 zero-day vulnerabilities in Google Chrome. Including two critical sandbox escapes. CVE-2026-5280 and CVE-2026-6297. One malicious tab. Full system compromise. These weren't easy bugs. Human auditors missed them. Automated fuzzers missed them. For decades. The AI found them in a single research run. The system is called AgentFlow. It coordinates multiple AI agents - each with different roles, tools, and feedback loops - optimizing the harness automatically until something breaks. The implications aren't theoretical. Every piece of critical software written before AI security auditing existed was reviewed by humans and fuzzers that are now provably less capable than what's available today. The question isn't whether AI can find vulnerabilities. It already has. The question is who finds the next ones first.

    Post summary

    Researchers report that an AI system, AgentFlow, discovered 10 zero‑day vulnerabilities in Google Chrome, including two critical sandbox escapes (CVE-2026-5280, CVE-2026-6297).

    0000075
    201 followersView on X
  • Tanat Tonguthaisri@gastronomy
    Disclosure

    Synthesizing Multi-Agent Harnesses for Vulnerability Discovery: LLM agents have begun to find real security vulnerabilities that human auditors and automated fuzzers missed for decades, in source-available targets where the analyst can bui… CVE-2026-6297).https://bit.ly/3QW5eQn

    Post summary

    LLM agents are reported to have discovered a new vulnerability (CVE-2026-6297) in source-available software, but no further technical, exploit, or mitigation details are shared.

    0000068
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6297 Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position to potentially perform a sandbox escape via a craf… https://www.cve.org/CVERecord?id=CVE-2026-6297

    Post summary

    The post announces CVE-2026-6297, a use‑after‑free vulnerability in Google Chrome leading to potential sandbox escape, without providing exploitation code or patch details.

    0000066
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6297 Use After Free in Google Chrome Proxy Prior to 147.0.7727.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6297 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet notes a use-after-free flaw in Chrome before version 147.0.7727, linking to a vulnerability details page without providing PoC, exploit, or patch information.

    0000042
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6297 Use after free in Proxy in Google Chrome prior to 147.0.7727.101 allowed an attacker in a privileged network position t… CVSS 8.3 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6297 #Google #CyberSecurity #InfoSec

    Post summary

    The note announces a high‑severity use‑after‑free vulnerability (CVE‑2026‑6297) affecting Chrome versions before 147.0.7727.101, with a CVSS score of 8.3 and further analysis linked to an external resource.

    000002
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more