Junglewise Threat Intelligence

CVE-2026-11307: Google Chrome use after free in PDFium

CVE-2026-11307 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's PDF viewing component, PDFium. An attacker could use a specially crafted PDF file to execute unauthorized code within the browser's security sandbox. While the impact is limited by the sandbox, it could lead to application crashes or be used as part of a more complex attack chain.

Technical details

A use-after-free (UAF) vulnerability exists in PDFium, the PDF engine used in Google Chrome, prior to version 149.0.7827.53. The flaw is triggered when the engine attempts to access memory that has already been freed, typically during the processing of a specially crafted PDF document. A remote, unauthenticated attacker can exploit this by enticing a user to open a malicious PDF file or visit a website hosting one. Successful exploitation allows for arbitrary code execution within the Chromium renderer sandbox. This issue is tracked as CWE-416 and has been patched in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-05: disclosed: CVE published to NVD

References

Related threats