
📄 CVE‑2026‑6306 – Google Chrome PDFium heap overflow (High): In Google Chrome prior to 147.0.7727.101, a heap buffer overflow in PDFium’s PDF parsing lets remote attackers trigger out‑of‑bounds writes by luring a user into opening a malicious PDF, enabling code execution in the PDF renderer context. CVSS 8.8 (v3.0), published 2026‑04‑16; fixed in Chrome 147.0.7727.101, so update Chrome/Chromium‑based browsers immediately. https://www.tenable.com/cve/CVE-2026-6306 #CVE20266306 #Chrome #PDFium #RCE #BrowserSecurity
Post summary
CVE-2026-6306 is a heap overflow in Chrome’s PDFium component that allows remote code execution via malicious PDFs. Google has released a patch in Chrome 147.0.7727.101, and users are advised to update immediately.




