Junglewise Threat Intelligence

CVE-2026-11303: Google Chrome use after free in PDFium

CVE-2026-11303 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's PDF rendering engine, PDFium. By tricking a user into opening a specially crafted PDF file, a remote attacker could execute unauthorized code within the browser's security sandbox. While the impact is limited by the sandbox, it could lead to browser instability or be used as part of a more complex attack chain.

Technical details

A use-after-free (UAF) vulnerability was identified in PDFium, the PDF rendering engine used in Google Chrome. The flaw is triggered when the engine incorrectly manages memory lifecycle during the processing of a specially crafted PDF document. A remote attacker can exploit this by hosting a malicious PDF file or embedding it in a website, leading to arbitrary code execution within the confines of the Chromium sandbox. The vulnerability is addressed in Chrome version 149.0.7827.53. Chromium developers have classified this with a 'Low' security severity.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
  • 2026-06-05: disclosed: NVD publication date

References

Related threats