CVE-2026-6307: Type Confusion in Google Chrome
A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI driver to conceal command-and-control ports, and manipulates Windows Filtering Platform to block security products. Its most distinctive feature is a covert control channel where commands are delivered through registry writes monitored by a kernel callback, bypassing network-based detection. The rootkit masquerades as a legitimate Microsoft service and minifilter driver, includes anti-sandbox checks via hypervisor time-stamp counter probing, and exposes over two dozen kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. Infrastructure remains operational with C2 server at 43.160.247.24.
AI Analysis
Technical Summary
CVE-2026-6307 involves a type confusion vulnerability in Google Chrome that enables a complex Windows kernel-mode rootkit to compromise system security. The rootkit uses advanced techniques such as patching ETW, Direct Kernel Object Manipulation (DKOM), hooking the NSI driver, and manipulating the Windows Filtering Platform to evade detection and hide malicious activity. It establishes a covert control channel via registry writes monitored by a kernel callback, bypassing network-based detection mechanisms. The rootkit impersonates legitimate Microsoft services and minifilter drivers, performs anti-sandbox checks using hypervisor time-stamp counter probing, and exposes numerous kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. The vulnerability affects Chrome versions up to and including 147.0.7727.101. Google has released a patch to address this issue.
Potential Impact
Successful exploitation allows attackers to gain kernel-level control over the Windows system, enabling them to hide processes, network connections, and security products, execute arbitrary code with high privileges, and maintain persistent covert communication channels. This leads to full system compromise with confidentiality, integrity, and availability impacts rated high.
Mitigation Recommendations
A patch for this vulnerability is available from Google. Users and administrators should apply the official Chrome update to versions later than 147.0.7727.101 as soon as possible to remediate this issue. No additional mitigation steps are indicated by the vendor advisory.
Indicators of Compromise
- hash: 4e95aba17c1a423cda5cc9f9f04f7cf8db17e294eb31ed1aa85063601b82fe8d
- cve: CVE-2026-6307
- hash: b5f122f3f07f618c0a7678fa40801faa
- hash: 7440358c5041eba34e8673100989df756a6426da
- ip: 43.160.247.24
- ip: 91.99.165.207
CVE-2026-6307: Type Confusion in Google Chrome
Description
A sophisticated Windows kernel-mode rootkit initially misidentified as Cobalt Strike Beacon operates from Ring 0 to compromise system security. The driver patches Event Tracing for Windows (ETW), employs Direct Kernel Object Manipulation (DKOM) to hide processes, hooks the NSI driver to conceal command-and-control ports, and manipulates Windows Filtering Platform to block security products. Its most distinctive feature is a covert control channel where commands are delivered through registry writes monitored by a kernel callback, bypassing network-based detection. The rootkit masquerades as a legitimate Microsoft service and minifilter driver, includes anti-sandbox checks via hypervisor time-stamp counter probing, and exposes over two dozen kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. Infrastructure remains operational with C2 server at 43.160.247.24.
CVSS v3.1
Score 8.8high
Affected software
Chrome
pkg:github/chromium/chromiumRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-6307 involves a type confusion vulnerability in Google Chrome that enables a complex Windows kernel-mode rootkit to compromise system security. The rootkit uses advanced techniques such as patching ETW, Direct Kernel Object Manipulation (DKOM), hooking the NSI driver, and manipulating the Windows Filtering Platform to evade detection and hide malicious activity. It establishes a covert control channel via registry writes monitored by a kernel callback, bypassing network-based detection mechanisms. The rootkit impersonates legitimate Microsoft services and minifilter drivers, performs anti-sandbox checks using hypervisor time-stamp counter probing, and exposes numerous kernel primitives including arbitrary physical memory access, process injection, hardware input spoofing, and reflective PE loading. The vulnerability affects Chrome versions up to and including 147.0.7727.101. Google has released a patch to address this issue.
Potential Impact
Successful exploitation allows attackers to gain kernel-level control over the Windows system, enabling them to hide processes, network connections, and security products, execute arbitrary code with high privileges, and maintain persistent covert communication channels. This leads to full system compromise with confidentiality, integrity, and availability impacts rated high.
Mitigation Recommendations
A patch for this vulnerability is available from Google. Users and administrators should apply the official Chrome update to versions later than 147.0.7727.101 as soon as possible to remediate this issue. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-04-14T18:12:23.524Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html","vendor":"Google"}]
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash4e95aba17c1a423cda5cc9f9f04f7cf8db17e294eb31ed1aa85063601b82fe8d | — | |
hashb5f122f3f07f618c0a7678fa40801faa | — | |
hash7440358c5041eba34e8673100989df756a6426da | — |
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2026-6307 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip43.160.247.24 | — | |
ip91.99.165.207 | — |
Threat ID: 69dfe7b982d89c981f913cd4
Added to database: 04/15/2026, 19:32:09 UTC
Last enriched: 08/04/2026, 12:37:59 UTC
Last updated: 09/14/2026, 22:44:06 UTC
Views: 151
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.