Description
Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use after free in PDFium permits a remote attacker to trigger heap corruption through a specially crafted PDF file presented to Google Chrome. The flaw may allow arbitrary code execution or denial of service by corrupting memory structures during PDF processing. The vulnerability is a memory‑management weakness classified as CWE‑416 and is rated as high severity by Chromium security.

Affected Systems

Google Chrome versions prior to 148.0.7778.216 are affected. Users who have not updated Chrome to at least 148.0.7778.216 or a later release are vulnerable. The issue is confined to the built‑in PDF viewer component within Chrome.

Risk and Exploitability

Exploitation requires the victim to open a malicious PDF file, which is a typical remote–vector scenario. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. However, the CVSS score of 8.8, which is considered high, and the potential for arbitrary code execution mean that the risk is significant for exposed systems. The most efficient attack path is to deliver a malicious PDF via email or web download and entice the user to view it in Chrome.

Generated by OpenCVE AI on May 29, 2026 at 13:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 148.0.7778.216 or later, which contains the fixed PDFium memory‑management patch.
  • If an update is not immediately possible, disable the PDF viewer in Chrome settings or use a third‑party PDF reader that does not rely on the vulnerable PDFium component.
  • Ensure the operating system and application sandboxing features remain enabled so that any potential exploit is confined and cannot affect other system components.

Generated by OpenCVE AI on May 29, 2026 at 13:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Use after free in PDFium
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 28 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T18:01:06.874Z

Reserved: 2026-05-28T17:25:11.764Z

Link: CVE-2026-10002

cve-icon Vulnrichment

Updated: 2026-05-29T18:01:03.279Z

cve-icon NVD

Status : Modified

Published: 2026-05-28T23:16:41.970

Modified: 2026-05-29T19:16:22.323

Link: CVE-2026-10002

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-10002 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T14:00:20Z

Weaknesses