Junglewise Threat Intelligence

CVE-2026-11305: Google Chrome use after free in PDFium

CVE-2026-11305 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability was identified in its PDFium component, which is responsible for displaying PDF files within the browser. An attacker could exploit this by tricking a user into opening a specially crafted PDF file, potentially allowing the attacker to run unauthorized code on the user's computer, though the impact is limited by the browser's security sandbox.

Technical details

A use-after-free (UAF) vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome, prior to version 149.0.7827.53. The flaw is triggered when the engine improperly handles memory objects during the processing of a specially crafted PDF file. A remote, unauthenticated attacker can exploit this by hosting a malicious PDF or sending it to a victim, leading to arbitrary code execution (ACE) within the context of the Chrome renderer sandbox. While UAF bugs often lead to high-impact exploits, Chromium has rated this specific instance as Low severity. Users should update to version 149.0.7827.53 or later to mitigate the risk.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 promoted to stable channel.
  • 2026-06-05: disclosed: NVD publication date.

References

Related threats