Junglewise Threat Intelligence

CVE-2026-18012: Google Chrome use after free in PDFium

CVE-2026-18012 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's PDF viewing component, PDFium. This flaw could allow a remote attacker to execute unauthorized code on a user's computer if the user opens a specially crafted PDF file. While the impact is limited by the browser's security sandbox, it still represents a risk to the integrity of the application and user data.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in the PDFium component of Google Chrome. The flaw is triggered when processing a specially crafted PDF file, which can lead to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to open a malicious PDF, potentially achieving arbitrary code execution within the browser's sandbox environment. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats