Executive brief
A security vulnerability exists in the PDF viewing component of Google Chrome on Windows. An attacker could exploit this by tricking a user into opening a malicious PDF file and performing specific mouse or keyboard actions, potentially allowing the attacker to run unauthorized code on the user's computer. While the impact is limited by Chrome's security sandbox, it poses a significant risk to data privacy and system integrity.
Technical details
A heap-based buffer overflow (CWE-122) exists in PDFium, the PDF rendering engine used by Google Chrome. The vulnerability is reachable by a remote attacker who provides a specially crafted PDF file. Exploitation requires the victim to perform specific, unspecified UI gestures, making the attack complexity high. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. The issue was addressed in Google Chrome version 147.0.7727.101 for Windows.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-04-15: disclosed
- 2026-04-15: patched: Fixed in version 147.0.7727.101
- 2026-04-15: advisory