
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6306 is a heap buffer overflow vulnerability in the PDFium component of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted PDF file. It was reported by researcher 86ac1f1587b71893ed2ad792cd7dde32 on March 27, 2026, and publicly disclosed on April 15, 2026, as part of a 31-fix Chrome stable channel update. All Google Chrome versions prior to 147.0.7727.101 are affected, as is Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), occurring within Chrome's PDFium PDF rendering library. When Chrome processes a specially crafted PDF file, insufficient bounds checking in PDFium allows an attacker to write data beyond the bounds of a heap-allocated buffer, potentially corrupting adjacent memory structures. Exploitation requires user interaction — specifically, a victim must open a malicious PDF file in an affected Chrome browser. The attack vector is network-based with low complexity, requiring no privileges from the attacker (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox environment, impacting confidentiality, integrity, and availability at a high level. While sandbox containment limits the immediate blast radius, code execution within the sandbox can serve as a stepping stone for sandbox escape chains, potentially leading to full system compromise. All users running Google Chrome prior to 147.0.7727.101 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based), are at risk (GitHub Advisory, Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.071%, indicating a low near-term probability of exploitation. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Bug details in the Chromium issue tracker (issue 496907110) remain restricted pending broad user adoption of the patch (Chrome Releases).
chrome.exe or chrome (e.g., cmd.exe, powershell.exe, bash, curl, wget) following PDF rendering; unexpected process injection activity originating from Chrome renderer processes.Google has released a fix in Chrome version 147.0.7727.101 (Linux) and 147.0.7727.101/102 (Windows/Mac); users should update immediately via Chrome's built-in update mechanism (Settings → Help → About Google Chrome). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a precautionary measure, users should avoid opening PDF files from untrusted or unknown sources in Chrome until the update is applied. Organizations may consider enforcing PDF file handling through dedicated, sandboxed PDF readers rather than the browser for sensitive environments (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large 31-fix Chrome security update, which drew coverage from security news outlets including CyberPress and TechLomedia, highlighting the breadth of the release and urging immediate updates. The CIS issued an advisory noting that multiple Chrome vulnerabilities in this batch could allow arbitrary code execution. F5 Labs included it in their weekly threat bulletin for April 22, 2026. No notable individual researcher commentary or significant social media debate specific to CVE-2026-6306 has been identified beyond standard vulnerability tracking and aggregation (Chrome Releases).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."