Executive brief
Google Chrome's PDF viewer (PDFium) contained a memory management flaw that could be triggered by a malicious PDF file. If a user opens a specially crafted PDF, an attacker could potentially read sensitive information from the computer's memory or cause the browser to crash. This affects users on Windows, Mac, Linux, and Android who have not updated to version 55 or later.
Technical details
A use-after-free (UAF) vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been deallocated during the processing of a malformed PDF document. A remote attacker can exploit this by enticing a user to open a specially crafted PDF file, leading to an out-of-bounds (OOB) memory read. This can result in the disclosure of sensitive information from the process memory or a denial-of-service (browser crash). The issue was addressed in Chrome version 55.0.2883.75 for desktop and 55.0.2883.84 for Android.
Affected products
- Google Chrome Prior to 55.0.2883.75 (Mac, Windows, Linux); Prior to 55.0.2883.84 (Android)
Timeline
- 2016-12-01: advisory: Google released Chrome 55.0.2883.75 with the fix
- 2016-12-07: advisory: Red Hat issued security advisory RHSA-2016:2919
- 2017-01-19: disclosed: NVD publication date