Junglewise Threat Intelligence

CVE-2026-93381: Google Chrome buffer overflow in PDFium

CVE-2026-93381 · Severity: high · CVSS 8.8 · Published 2026-09-17

Executive brief

Google Chrome contains a buffer overflow vulnerability in PDFium, its PDF rendering engine. A remote attacker could exploit this by tricking a user into opening a malicious PDF file, potentially allowing arbitrary code execution within Chrome's sandbox environment. While sandboxed, this could still lead to browser compromise and exposure of user data.

Technical details

A buffer overflow exists in PDFium, Google Chrome's PDF rendering library, allowing attackers to write beyond allocated memory bounds. The vulnerability is triggered by a specially crafted PDF file delivered to a user, requiring social engineering (user interaction) to open the malicious file. An attacker can achieve arbitrary code execution within the browser's sandbox isolation layer. The vulnerability affects Windows versions of Chrome prior to 153.0.8010.52 and was patched in the September 17, 2026 stable release.

Affected products

  • Google Chrome prior to 153.0.8010.52 on Windows

Timeline

  • 2026-09-03: disclosed: Reported by SeungMyung Lee and Siung kim
  • 2026-09-17: patched: Fixed in Chrome 153.0.8010.52

References

Related threats