Google Chrome PrivateAI Use-After-Free Vulnerability Allowing Sandbox Escape

Vulnerability

A use-after-free vulnerability has been identified in the PrivateAI component of Google Chrome, affecting versions prior to 147.0.7727.55. This vulnerability could allow a remote attacker to perform a sandbox escape by convincing a user to engage in specific UI gestures while interacting with a crafted HTML page.

Impact

Exploitation of this vulnerability could lead to a sandbox escape, allowing potentially malicious actions to be performed outside of the intended security confines.

Remediation

Users can update to Google Chrome version 147.0.7727.55 or later to address this vulnerability.

Added: Apr 8, 2026, 11:54 PM
Updated: Apr 8, 2026, 11:54 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.2
remediation
7.7
relevance
5.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.