Executive brief
A vulnerability exists in Google Chrome's PDF viewing component that could allow a remote attacker to execute malicious code. By tricking a user into opening a specially crafted PDF file, an attacker could gain unauthorized access within the browser's restricted environment (sandbox). This could lead to further exploitation of the system or interference with the user's browsing session.
Technical details
A use-after-free (UAF) vulnerability exists in the PDF engine of Google Chrome. The flaw is triggered when the browser improperly manages memory during the processing of PDF content, allowing an attacker to reference memory after it has been freed. A remote, unauthenticated attacker can exploit this by enticing a user to open a specially crafted PDF file. Successful exploitation allows for arbitrary code execution within the Chromium sandbox. This issue is addressed in Google Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.
Affected products
- Google Chrome Prior to 149.0.7827.103
Timeline
- 2026-05-21: disclosed: Reported by Google internal researchers
- 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
- 2026-06-09: advisory: NVD publication date