Executive brief
A vulnerability exists in Google Chrome's PDF rendering engine, PDFium. By tricking a user into opening a specially crafted PDF file, a remote attacker could execute unauthorized code within the browser's security sandbox. While the impact is limited by the sandbox, it could lead to browser instability or be used as part of a more complex attack chain.
Technical details
A use-after-free (UAF) vulnerability was identified in PDFium, the PDF rendering engine used in Google Chrome. The flaw is triggered when the engine incorrectly manages memory lifecycle during the processing of a specially crafted PDF document. A remote attacker can exploit this by hosting a malicious PDF file or embedding it in a website, leading to arbitrary code execution within the confines of the Chromium sandbox. The vulnerability is addressed in Chrome version 149.0.7827.53. Chromium developers have classified this with a 'Low' security severity.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
- 2026-06-05: disclosed: NVD publication date