VORANT. Threat Intelligence Sign in Get the full feed

Chrome 147 patches 25 code-execution flaws

medium vulnerability

Google Chrome versions before 147.0.7727.101/102 contain multiple memory-corruption bugs that could let attackers run arbitrary code; no in-the-wild exploitation reported yet.

MS-ISAC issued an advisory covering 25 vulnerabilities patched in Chrome 147.0.7727.101/102 for Windows, macOS, and Linux. The flaws span heap buffer overflows, use-after-free conditions, type confusion, and out-of-bounds read/write bugs across core browser components including ANGLE, Skia, V8, Turbofan, PDFium, GPU, and Codecs. Successful exploitation of the most severe issues could allow arbitrary code execution in the context of the logged-in user, potentially enabling installation of programs, data manipulation, or creation of new accounts, with impact scaled by the victim's account privileges.

No active exploitation has been reported at the time of publication; this is a proactive patch advisory rather than a response to observed attacks. The likely attack vector for these classes of bugs is drive-by compromise via malicious or compromised web content. MS-ISAC recommends immediate patch deployment, least-privilege enforcement, browser sandboxing/exploit protection, DNS and URL filtering, and user awareness training as mitigations.

Mentioned in this report

Vulnerabilities CVE-2026-6296CVE-2026-6297CVE-2026-6298CVE-2026-6299CVE-2026-6300CVE-2026-6301CVE-2026-6302CVE-2026-6303CVE-2026-6304CVE-2026-6305CVE-2026-6306CVE-2026-6307CVE-2026-6308CVE-2026-6309CVE-2026-6310CVE-2026-6311CVE-2026-6312CVE-2026-6313CVE-2026-6314CVE-2026-6315CVE-2026-6316CVE-2026-6317CVE-2026-6318CVE-2026-6319CVE-2026-6358CVE-2026-6359CVE-2026-6360CVE-2026-6361CVE-2026-6362CVE-2026-6363CVE-2026-6364

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-037

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free