Skip to main content
EPSS 0.4%top 70%

CVE-2026-6307: Type Confusion in Google Chrome

0
High
Published: 08/03/2026 (08/03/2026, 09:04:41 UTC)
Source: CVE Database V5
Vendor/Project: Google
Product: Chrome

Description

A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI driver to conceal command-and-control ports, and manipulates Windows Filtering Platform to block security products. Its most distinctive feature is a covert control channel where commands are delivered through registry writes monitored by a kernel callback, bypassing network-based detection. The rootkit masquerades as a legitimate Microsoft service and minifilter driver, includes anti-sandbox checks via hypervisor time-stamp counter probing, and exposes over two dozen kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. Infrastructure remains operational with C2 server at 43.160.247.24.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

Google

Chrome

Affected versions
>=147.0.7727.101 <147.0.7727.101
GitHub Actionsmore threats →ai
chromium/chromium
pkg:github/chromium/chromium
Affected versions
<147.0.7727.101

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/04/2026, 12:37:59 UTC

Technical Analysis

CVE-2026-6307 involves a type confusion vulnerability in Google Chrome that enables a complex Windows kernel-mode rootkit to compromise system security. The rootkit uses advanced techniques such as patching ETW, Direct Kernel Object Manipulation (DKOM), hooking the NSI driver, and manipulating the Windows Filtering Platform to evade detection and hide malicious activity. It establishes a covert control channel via registry writes monitored by a kernel callback, bypassing network-based detection mechanisms. The rootkit impersonates legitimate Microsoft services and minifilter drivers, performs anti-sandbox checks using hypervisor time-stamp counter probing, and exposes numerous kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. The vulnerability affects Chrome versions up to and including 147.0.7727.101. Google has released a patch to address this issue.

Potential Impact

Successful exploitation allows attackers to gain kernel-level control over the Windows system, enabling them to hide processes, network connections, and security products, execute arbitrary code with high privileges, and maintain persistent covert communication channels. This leads to full system compromise with confidentiality, integrity, and availability impacts rated high.

Mitigation Recommendations

A patch for this vulnerability is available from Google. Users and administrators should apply the official Chrome update to versions later than 147.0.7727.101 as soon as possible to remediate this issue. No additional mitigation steps are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
Chrome
Date Reserved
2026-04-14T18:12:23.524Z
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html","vendor":"Google"}]

Indicators of Compromise

Hash

ValueDescriptionCopy
hash4e95aba17c1a423cda5cc9f9f04f7cf8db17e294eb31ed1aa85063601b82fe8d
hashb5f122f3f07f618c0a7678fa40801faa
hash7440358c5041eba34e8673100989df756a6426da

Cve

ValueDescriptionCopy
cveCVE-2026-6307

Ip

ValueDescriptionCopy
ip43.160.247.24
ip91.99.165.207

Threat ID: 69dfe7b982d89c981f913cd4

Added to database: 04/15/2026, 19:32:09 UTC

Last enriched: 08/04/2026, 12:37:59 UTC

Last updated: 09/14/2026, 22:44:06 UTC

Views: 151

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses