Executive brief
A security vulnerability has been identified in Google Chrome's PDF viewing component, PDFium. An attacker could exploit this flaw by tricking a user into opening a specially crafted PDF file, potentially leading to unauthorized code execution or a browser crash. This could result in the compromise of sensitive user data or a disruption of browser operations.
Technical details
A use-after-free (UAF) vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome. The flaw is triggered when the engine incorrectly manages memory during the processing of a specially crafted PDF file, leading to heap corruption. A remote, unauthenticated attacker can exploit this by inducing a user to open a malicious PDF document. Successful exploitation could allow the attacker to execute arbitrary code within the context of the browser's sandbox or cause the browser to crash. The vulnerability is addressed in Google Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
- 2026-05-28: disclosed: CVE published to NVD dataset