Executive brief
A security vulnerability exists in Google Chrome's PDF viewing component, PDFium. By tricking a user into opening a specially crafted PDF file, a remote attacker could execute unauthorized code on the user's computer. While the attack is limited by the browser's security sandbox, it could still lead to data theft or further system compromise.
Technical details
A heap buffer overflow vulnerability (CWE-122) exists in PDFium, the PDF rendering engine used in Google Chrome. The flaw is triggered when the browser processes a maliciously crafted PDF file. A remote, unauthenticated attacker can exploit this by hosting the file on a website or sending it via email, requiring the user to open or view the document. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. This issue was addressed in Chrome version 147.0.7727.101 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-03-26: other: Vulnerability reported to Chromium project
- 2026-04-15: disclosed: Initial public disclosure
- 2026-04-15: patched: Fixed in Chrome version 147.0.7727.101