Junglewise Threat Intelligence

CVE-2026-9958: Google Chrome use after free in PDFium

CVE-2026-9958 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's PDF viewing component, PDFium. An attacker could use a specially crafted PDF file to cause memory corruption, potentially leading to a browser crash or unauthorized code execution. This could allow an attacker to compromise a user's computer if they view a malicious PDF document or visit a website hosting one.

Technical details

A use-after-free (UAF) vulnerability exists in PDFium, the PDF rendering engine used in Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been deallocated during the processing of a specially crafted PDF document. This memory corruption (heap corruption) can be leveraged by a remote, unauthenticated attacker to achieve arbitrary code execution within the context of the browser's renderer process. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats