Description
Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw in the PDF rendering engine of Google Chrome allows a remote attacker to execute arbitrary code inside the sandbox through a crafted HTML page. The vulnerability can lead to complete compromise of the affected browser instance. It is classified as a high‑severity flaw (CWE-416).

Affected Systems

Google Chrome versions prior to 155.0.8059.39 are affected. The flaw exists in the PDF handling subsystem, and any user who opens a maliciously crafted HTML page that references a PDF can be targeted.

Risk and Exploitability

The standard CVSS score of 8.8 indicates a high severity, and the vulnerability is not currently listed in the CISA KEV catalog. The EPSS score is unavailable, but the nature of the flaw suggests that exploitation requires an attacker-controlled web page to be accessed by a user. Because the attack leverages the browser’s PDF renderer, it is limited to users who load the malicious page, yet the impact remains significant if exploited.

Generated by OpenCVE AI on October 7, 2026 at 02:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or newer.
  • Temporarily disable the embedded PDF viewer or block PDF rendering via browser flags until the update is applied.
  • Monitor for anomalous PDF loading activity and block suspicious URLs that may host malicious PDFs.

Generated by OpenCVE AI on October 7, 2026 at 02:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 07 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Title Use After Free in PDF Rendering Allows Remote Code Execution in Google Chrome

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use after free in PDF in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:55:57.114Z

Reserved: 2026-10-06T16:38:46.410Z

Link: CVE-2026-106421

cve-icon Vulnrichment

Updated: 2026-10-06T19:40:54.943Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:18:11.893

Modified: 2026-10-07T13:10:20.327

Link: CVE-2026-106421

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:00:08Z

Weaknesses