Executive brief
A security vulnerability exists in the PDF viewing component of the Google Chrome web browser. By tricking a user into opening a specially crafted PDF file, a remote attacker could potentially crash the browser or execute unauthorized code on the user's device. This could lead to the theft of sensitive data or a complete compromise of the affected system.
Technical details
A use-after-free (UAF) vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome and Chromium. The flaw is triggered when the engine incorrectly manages memory during the processing of a malformed PDF document. A remote attacker can exploit this by hosting a malicious PDF file and enticing a user to view it, leading to heap corruption. Successful exploitation could allow for arbitrary code execution within the context of the browser's sandbox or a denial-of-service (browser crash). The issue was resolved in Chrome version 55.0.2883.75 for desktop platforms and 55.0.2883.84 for Android.
Affected products
- Google Chrome prior to 55.0.2883.75 (Desktop); prior to 55.0.2883.84 (Android)
- Google Chromium prior to 55.0.2883.75
Timeline
- 2016-12-01: patched: Chrome Stable Channel Update for Desktop released
- 2016-12-05: advisory: Gentoo Linux security advisory published
- 2016-12-07: advisory: Red Hat security advisory published
- 2017-01-19: disclosed: NVD publication date