Impact
A use‑after‑free flaw in Chrome’s PDF rendering engine permits an attacker to trigger arbitrary code execution inside the browser’s sandbox. The defect occurs after freeing memory associated with a PDF object, allowing crafted input to corrupt execution flow and run attacker‑supplied code while the browser remains under sandbox restrictions. The attacker can run arbitrary code inside the browser sandbox, which is a high‑risk scenario within that confined environment.
Affected Systems
Google Chrome browsers with versions earlier than 149.0.7827.53 are affected. All operating systems that ship this Chrome version are susceptible, including Windows, macOS, Linux, and Chrome OS. No other Chrome releases are mentioned as vulnerable.
Risk and Exploitability
The vulnerability’s CVSS score is 8.8, indicating high severity, and its EPSS score is < 1%. It is not in CISA’s KEV catalog. The likely attack vector is a remote exploitation that requires a user to open a specifically crafted PDF file. The user’s interaction with the PDF triggers the use‑after‑free, leading to code execution. Given the low EPSS estimate, the probability of widespread exploitation remains low, but the high severity and requirement of a user to engage with a malicious file suggest the risk is significant in environments with exposed users.
OpenCVE Enrichment
Debian DSA