CVE-2026-6303
Published: 15 April 2026
Summary
CVE-2026-6303 is a high-severity Use After Free (CWE-416) vulnerability in Google Chrome. Its CVSS base score is 8.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Drive-by Compromise (T1189); ranked at the 28.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-2 (Flaw Remediation) and RA-5 (Vulnerability Monitoring and Scanning).
Deeper analysis
CVE-2026-6303 is a use-after-free vulnerability (CWE-416) in the Codecs component of Google Chrome prior to version 147.0.7727.101. Published on 2026-04-15, it carries a CVSS v3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and is classified as High severity by Chromium security.
A remote attacker can exploit this flaw by crafting an HTML page that triggers the use-after-free condition in Codecs, enabling arbitrary code execution within the browser's sandbox. Exploitation requires user interaction, such as visiting the malicious page, but needs no privileges or special access.
Mitigation is available via the Chrome stable channel update to version 147.0.7727.101 or later. Additional details are provided in the Chrome Releases blog post at https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html and the Chromium issue tracker at https://issues.chromium.org/issues/496282147.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-23048
Vulnerability details
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Use-after-free in Chrome Codecs enables arbitrary code execution via crafted HTML page, directly facilitating drive-by compromise (T1189) and exploitation for client execution (T1203) with user interaction.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Directly remediates the use-after-free vulnerability in Chrome's Codecs by requiring timely identification, reporting, and patching to version 147.0.7727.101 or later.
Implements memory safeguards such as ASLR and non-executable memory that mitigate use-after-free exploitation by protecting against unauthorized access and code execution.
Enables scanning to identify systems running vulnerable Chrome versions prior to 147.0.7727.101, facilitating prioritization and remediation.