Junglewise Threat Intelligence

CVE-2026-9957: Google Chrome use after free in PDF

CVE-2026-9957 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the PDF viewing component of Google Chrome. By tricking a user into opening a specially crafted PDF file, a remote attacker could execute malicious code on the user's computer. While the attack is limited by the browser's security sandbox, it could lead to unauthorized data access or further system compromise if combined with other flaws.

Technical details

A use-after-free (UAF) vulnerability exists in the PDF engine of Google Chrome (CWE-416). The flaw is triggered when the browser incorrectly manages memory during the processing of a specially crafted PDF document. A remote, unauthenticated attacker can exploit this by hosting a malicious PDF file and enticing a user to view it. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. Google has addressed this issue in version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats