Executive brief
A vulnerability exists in Google Chrome's PDF viewing component, PDFium. This flaw could allow a remote attacker to execute unauthorized code on a user's computer if the user opens a specially crafted PDF file. While the impact is limited by the browser's security sandbox, it still represents a risk to the integrity of the application and user data.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the PDFium component of Google Chrome. The flaw is triggered when processing a specially crafted PDF file, which can lead to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to open a malicious PDF, potentially achieving arbitrary code execution within the browser's sandbox environment. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date