Junglewise Threat Intelligence

CVE-2026-87585: Google Chrome double free in PDFium

CVE-2026-87585 · Severity: high · CVSS 8.8 · Published 2026-09-09

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome is a web browser used by billions of people to access websites and web applications. A double free vulnerability in the PDF rendering engine (PDFium) could allow an attacker to execute malicious code on a user's computer by crafting a specially designed PDF file. This could lead to complete compromise of the browser process, theft of sensitive data, or installation of malware.

Technical details

A double free vulnerability exists in PDFium, the PDF rendering library used by Google Chrome on Windows. The vulnerability occurs when the same memory location is freed twice during PDF processing, leading to heap corruption. An attacker can exploit this by crafting a malicious PDF file that, when opened in Chrome, triggers the double free condition. The attack vector is network-based (no authentication required), and while the immediate impact is limited to the Chrome sandbox, successful exploitation could lead to arbitrary code execution within the sandbox process. Google released a fix in Chrome 153.0.8010.36 on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-07-30: disclosed: Vulnerability reported by Jeongkihyun
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36 released to stable channel
  • 2026-09-09: advisory: CVE-2026-87585 published

References

Related threats