Junglewise Threat Intelligence

CVE-2026-14108: Google Chrome use after free in PDFium

CVE-2026-14108 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's PDF viewing component, PDFium, contains a security vulnerability that could allow a remote attacker to execute unauthorized code. By tricking a user into opening a specially crafted PDF file, an attacker could potentially compromise the browser's security sandbox. While the impact is limited by the browser's internal security boundaries, it represents a risk to data integrity and system security for users on outdated versions.

Technical details

A use-after-free (UAF) vulnerability exists in the PDFium engine of Google Chrome. The flaw is triggered when the browser processes a specially crafted PDF file, leading to memory corruption. A remote, unauthenticated attacker can exploit this by hosting a malicious PDF and enticing a user to view it. Successful exploitation allows for arbitrary code execution within the constraints of the Chrome sandbox. The issue is addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats