Back

CRITICAL

chromium-browser: Type Confusion in Turbofan

Published Apr 15, 2026

Description

Type Confusion in Turbofan in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Chrome
Published Apr 15, 2026
Updated May 26, 2026
Reserved Apr 14, 2026

CISA Vulnrichment

Updated Apr 16, 2026

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Apr 15, 2026
Bugzilla 2458785

ENISA EUVD

Assigner Chrome
Published Apr 15, 2026
Updated May 26, 2026

GitHub

No data