Junglewise Threat Intelligence

CVE-2026-79119: Google Chrome use-after-free in PDF

CVE-2026-79119 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's PDF viewer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code within the browser sandbox by opening a specially crafted PDF file. An attacker could exploit this to run malicious code with the privileges of the Chrome process, potentially leading to data theft, system compromise, or further attacks on the user's computer.

Technical details

A use-after-free vulnerability exists in Google Chrome's PDF handling code prior to version 152.0.7977.65. The vulnerability allows a remote attacker to exploit memory corruption by crafting a malicious PDF file that triggers the use of freed memory. The attack vector is network-based and requires only that a user open or be tricked into opening the crafted PDF in Chrome. While execution is confined to the sandbox, the attacker can achieve arbitrary code execution within that sandbox context. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats