Junglewise Threat Intelligence

CVE-2026-11306: Google Chrome use after free in PDFium

CVE-2026-11306 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's PDF viewing component, PDFium. This flaw allows a remote attacker to potentially execute unauthorized code on a user's computer if the user opens a specially crafted PDF file. While the impact is limited by Chrome's security sandbox, it could still lead to localized service disruptions or be used as part of a more complex attack chain.

Technical details

A use-after-free (UAF) vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome. The flaw is triggered when the engine incorrectly manages memory during the processing of a specially crafted PDF file. A remote, unauthenticated attacker can exploit this by inducing a user to open a malicious PDF, leading to arbitrary code execution within the constraints of the Chrome sandbox. This vulnerability was addressed in Google Chrome version 149.0.7827.53. The Chromium project classified this issue with a 'Low' security severity.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update.
  • 2026-06-05: disclosed: NVD publication date.

References

Related threats