Executive brief
Google Chrome is a widely used web browser. A vulnerability in its PDF viewing component (PDFium) could allow a remote attacker to execute malicious code on a user's computer if they are tricked into opening a specially crafted PDF file. While the attack is limited by the browser's security sandbox, it still poses a significant risk to data integrity and system security.
Technical details
A use-after-free (UAF) vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome. The flaw is triggered when the engine incorrectly manages memory during the processing of a specially crafted PDF document. A remote, unauthenticated attacker can exploit this by hosting a malicious PDF file and inducing a user to view it. Successful exploitation allows for arbitrary code execution within the context of the Chrome renderer sandbox. The issue is addressed in Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date