CVE-2026-6303: Use after free in Codecs
Chromium: CVE-2026-6303 Use after free in Codecs
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-6303?
CVE-2026-6303 is classified as a high-severity vulnerability due to its potential for exploitation via a use-after-free condition.
How do I fix CVE-2026-6303?
To address CVE-2026-6303, update Google Chrome to version 147.0.7727.101 or later, or ensure Microsoft Edge is updated to a version containing the fix.
What types of software are affected by CVE-2026-6303?
CVE-2026-6303 affects Google Chrome versions before 147.0.7727.101 and Microsoft Edge (Chromium-based) before a certain security update.
Is CVE-2026-6303 present on macOS or Linux systems?
CVE-2026-6303 does not affect macOS or Linux systems as per the available information.
Can CVE-2026-6303 be exploited by attackers?
Yes, CVE-2026-6303 can be exploited by attackers to execute arbitrary code and potentially compromise user systems.