CVE-2026-6304Disclosure(apple / chrome)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-16); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-04-15: 1Mentions · 2026-04-16: 3Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 3Technical Details · 2026-04-17: 104-1504-1604-17
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-163
Disclosure3
2026-04-171
Patch1
Full discourse5 posts
  • WindowsForum@windowsforum
    Patch

    🪟 Another browser bug, another “don’t worry, only a crafted page” moment. CVE-2026-6304 isn’t narrow—it’s use-after-free + sandbox escape risk, aka enterprise downtime bait. Fix fast. https://windowsforum.com/threads/cve-2026-6304-chrome-graphite-use-after-free-and-sandbox-escape-risk-147-0-7727-101.413845/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #EnterprisePatching #ChromeSecurityUpdate #Cve20266304 https://t.co/K98etrFuLB

    Post summary

    The tweet alerts to CVE‑2026‑6304, a use‑after‑free and sandbox escape in Chrome, and urges users to apply patches promptly.

    0000049
    1.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-6304 Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox … https://www.cve.org/CVERecord?id=CVE-2026-6304 ----- Traducción: CVE-2026-6304 Uso… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑6304, a use‑after‑free issue in Chrome’s Graphite rendering engine that could allow sandbox escape if the renderer is compromised, and directs readers to the official CVE record.

    0000038
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6304 Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox … https://www.cve.org/CVERecord?id=CVE-2026-6304

    Post summary

    The post announces CVE‑2026‑6304 as a use‑after‑free bug in Chrome’s Graphite engine, but it does not provide PoC, exploit, or patch details.

    00000126
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6304 Use After Free in Graphite in Google Chrome Prior to 147.0.7727.101 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6304

    Post summary

    CVE-2026-6304 is identified as a use‑after‑free flaw in Google Chrome's Graphite component prior to version 147.0.7727.101, with no PoC, exploit, or patch details provided in the text.

    0000045
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6304 Use after free in Graphite in Google Chrome prior to 147.0.7727.101 allowed a remote attacker who had compromised the r… CVSS 8.3 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6304 #Google #CyberSecurity #InfoSec

    Post summary

    CVE-2026-6304 is a use‑after‑free vulnerability in Google Chrome’s Graphite component, rated HIGH (CVSS 8.3) and affecting versions before 147.0.7727.101, with no PoC, exploit, patch, or evidence of active exploitation mentioned.

    000005
    145 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more