You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026-6361
About this tag
CVE-2026-6361 is a high-severity heap buffer overflow vulnerability in Google Chrome's PDFium component, patched in the April 15, 2026 Stable Channel update (version 147.0.7727.101). The flaw affects Chrome on Windows and could allow an attacker to execute code inside the browser sandbox by tricking a user into opening a crafted PDF. While exploitation requires specific user interaction, the widespread use of PDFium and remote delivery of malicious PDFs make this a meaningful risk for both enterprise and consumer environments. Users are advised to update Chrome to the latest version to mitigate the threat.
Google has patched a high-severity heap buffer overflow in PDFium that affects Chrome on Windows versions before 147.0.7727.101, closing off a path that could let an attacker execute code inside the browser sandbox through a crafted PDF. The fix landed in the April 15, 2026 Stable Channel...