Executive brief
A cryptographic flaw in Google Chrome's PDF viewer (PDFium) could allow an attacker to access sensitive information within encrypted PDF documents. By convincing a user to open a specially crafted file or visit a malicious site, an attacker could use brute-force techniques to bypass encryption protections. This could lead to the unauthorized disclosure of private data contained in supposedly secure PDF files.
Technical details
A cryptographic vulnerability (CWE-326: Inadequate Encryption Strength) exists in the PDFium component of Google Chrome. The flaw allows for the recovery of sensitive information from encrypted PDF documents through brute-force attacks. The attack vector is network-based and requires user interaction, typically involving a user opening a malicious PDF or navigating to a compromised webpage. Successful exploitation results in a loss of confidentiality for data protected by PDF encryption. The issue is resolved in Google Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-23: disclosed: Reported by mlafon
- 2026-04-07: patched: Chrome 147 stable channel update released
- 2026-04-08: advisory: NVD publication date