Junglewise Threat Intelligence

CVE-2026-6306: Google Chrome heap buffer overflow in PDFium

CVE-2026-6306 · Severity: high · CVSS 8.8 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's PDF viewing component, PDFium. By tricking a user into opening a specially crafted PDF file, a remote attacker could execute malicious code on the user's computer. While the code execution is restricted by Chrome's security sandbox, this flaw could lead to data theft or further system compromise if combined with other vulnerabilities.

Technical details

A heap-based buffer overflow (CWE-122) exists in the PDFium component of Google Chrome. The vulnerability is triggered when the browser processes a maliciously crafted PDF file. A remote, unauthenticated attacker can exploit this by hosting the file on a website or sending it via email, requiring minimal user interaction (opening the file). Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. Google has addressed this issue in version 147.0.7727.101 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-27: disclosed: Reported by security researcher 86ac1f1587b71893ed2ad792cd7dde32
  • 2026-04-15: patched: Fixed in Chrome version 147.0.7727.101/102
  • 2026-04-15: advisory

References