CVE-2026-6301Disclosure(apple / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-843

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-16)
  • 4 total mentions across 2 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-15: 1Mentions · 2026-04-16: 3PoC Mentioned / Linked · 2026-04-15: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 304-1504-16
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-163
Disclosure2General1
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6301 Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chrom… https://www.cve.org/CVERecord?id=CVE-2026-6301 ----- Traducción: CVE-2026-6301 Con… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-6301, a type confusion flaw in Chrome’s Turbofan engine that allows remote code execution inside a sandbox through a crafted HTML page.

    0000031
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6301 Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chrom… https://www.cve.org/CVERecord?id=CVE-2026-6301

    Post summary

    CVE-2026-6301 is a type confusion vulnerability in Google Chrome’s Turbofan, enabling remote attackers to run arbitrary code inside a sandbox through a crafted HTML page; no exploit code or patch information is provided in the text.

    00000253
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-6301 Type Confusion in Turbofan in Google Chrome Prior to 147.0... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6301 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet references CVE-2026‑6301, indicating a type‑confusion bug in Chrome’s Turbofan engine before version 147.0, and links to a vulnerability database, but does not provide PoC, exploit code, or patch information.

    0000062
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6301 Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6301 #Google #CyberSecurity #InfoSec

    Post summary

    New high‑severity type‑confusion vulnerability (CVE‑2026‑6301) in Chrome’s Turbofan enables remote code execution (CVSS 8.8); a full analysis is available online.

    000002
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more