Junglewise Threat Intelligence

CVE-2026-93382: Google Chrome use-after-free in PDFium

CVE-2026-93382 · Severity: high · CVSS 8.8 · Published 2026-09-17

Executive brief

Google Chrome's PDF rendering engine (PDFium) contains a use-after-free vulnerability that allows an attacker to execute arbitrary code within the browser's security sandbox. An attacker can exploit this by crafting a malicious HTML page that, when visited by a user, triggers the vulnerability and potentially compromises the affected system.

Technical details

This is a use-after-free vulnerability in PDFium, Google Chrome's PDF processing library. The flaw allows memory to be accessed after it has been freed, which can be exploited to achieve arbitrary code execution within the Chrome sandbox via a maliciously crafted HTML page. The vulnerability requires user interaction (visiting a malicious webpage) but does not require authentication. The vulnerability was patched in Chrome version 153.0.8010.52 and later. This defect was discovered by WinD39 (Huynh Dinh Vu) and reported on 2026-08-02.

Affected products

  • Google Chrome prior to 153.0.8010.52

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: patched: Fixed in Chrome 153.0.8010.52

References

Related threats