Executive brief
A vulnerability in Google Chrome's PDF viewing component could allow an attacker to execute malicious code on a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted PDF file and performing specific mouse or keyboard actions. If successful, this could allow the attacker to compromise the browser's security, though the impact is partially limited by Chrome's internal security sandbox.
Technical details
A use-after-free (UAF) vulnerability exists in the PDF engine of Google Chrome (Chromium). The flaw is triggered when the browser incorrectly manages memory during the processing of a specially crafted PDF file, specifically when a user is induced to perform certain UI gestures. A remote attacker can leverage this to achieve arbitrary code execution (ACE) within the context of the browser's sandbox. The vulnerability is tracked as CWE-416 and was addressed in the stable channel update to version 149.0.7827.53 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-10945 published.