Description
Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-04-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is a use‑after‑free bug in Chrome’s prerendering subsystem that allows a remote attacker to run arbitrary code by loading a specially crafted web page. The flaw arises after a page’s memory is freed but pointers remain, enabling code execution in the context of the victim browser session. It involves a use‑after‑free (CWE‑416) and may also lead to an information leakage (CWE‑825) when uninitialized memory is accessed. Chromium has rated the defect as Critical because successful exploitation bypasses normal privilege boundaries and can affect any user who visits a maliciously constructed site.

Affected Systems

Google Chrome browsers with versions prior to 147.0.7727.101 are impacted. The issue applies to all platforms that ship the desktop stable channel of Chrome where prerender is enabled. Users of any devices running assemblies of Chrome that have not applied the 147.0.7727.101 update are vulnerable.

Risk and Exploitability

An attacker can exploit this flaw remotely by delivering a crafted HTML page over HTTP or HTTPS, with no additional network access required beyond being able to visit the page. The expected attack vector is web‑based; the browser must process the page to trigger the use‑after‑free. The EPSS score indicates a low exploitation probability (<1%), and the vulnerability has not yet been listed on CISA’s Known Exploited Vulnerabilities catalog. Nevertheless, Chromium labels it Critical, and its CVSS score is 8.8, indicating that exploitation is highly feasible and would grant full code‑execution privileges on the victim machine.

Generated by OpenCVE AI on April 17, 2026 at 08:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 147.0.7727.101 or later to obtain the vendor‑supplied fix.
  • If upgrade is delayed, temporarily disable prerendering by navigating to chrome://flags/#enable-prerender and setting the flag to Disabled.
  • Monitor Chrome security advisories for additional guidance and policy changes.

Generated by OpenCVE AI on April 17, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6214-1 chromium security update
History

Fri, 17 Apr 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 16 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Prerender Enables Remote Code Execution in Chrome Google Chrome: Chromium: Google Chrome and Chromium: Arbitrary code execution via a crafted HTML page
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Critical


Wed, 15 Apr 2026 22:30:00 +0000

Type Values Removed Values Added
Title Use After Free in Prerender Enables Remote Code Execution in Chrome

Wed, 15 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 15 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Description Use after free in Prerender in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-16T03:55:53.177Z

Reserved: 2026-04-14T18:12:20.506Z

Link: CVE-2026-6299

cve-icon Vulnrichment

Updated: 2026-04-15T19:44:37.911Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-15T20:16:38.790

Modified: 2026-04-17T15:41:34.823

Link: CVE-2026-6299

cve-icon Redhat

Severity : Critical

Publid Date: 2026-04-15T19:04:47Z

Links: CVE-2026-6299 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T08:30:13Z

Weaknesses