Junglewise Threat Intelligence

CVE-2026-5889: Google Chrome cryptographic flaw in PDFium

CVE-2026-5889 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A cryptographic flaw in Google Chrome's PDF viewer (PDFium) could allow an attacker to access sensitive information within encrypted PDF documents. By convincing a user to open a specially crafted file or visit a malicious site, an attacker could use brute-force techniques to bypass encryption protections. This could lead to the unauthorized disclosure of private data contained in supposedly secure PDF files.

Technical details

A cryptographic vulnerability (CWE-326: Inadequate Encryption Strength) exists in the PDFium component of Google Chrome. The flaw allows for the recovery of sensitive information from encrypted PDF documents through brute-force attacks. The attack vector is network-based and requires user interaction, typically involving a user opening a malicious PDF or navigating to a compromised webpage. Successful exploitation results in a loss of confidentiality for data protected by PDF encryption. The issue is resolved in Google Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-23: disclosed: Reported by mlafon
  • 2026-04-07: patched: Chrome 147 stable channel update released
  • 2026-04-08: advisory: NVD publication date

References

Related threats