Impact
The vulnerability is a use after free in the PDFium rendering engine of Google Chrome that permits a heap corruption through a maliciously crafted PDF file. This is a manifestation of CWE‑416 (Use after Free) and potentially CWE‑825 (Stack and Heap Corruption), allowing attackers to potentially execute arbitrary code from the victim's system.
Affected Systems
Google Chrome versions prior to 149.0.7827.53, specifically the PDFium component included in those Chrome builds.
Risk and Exploitability
Based on the description, the likely attack vector is delivery of a malicious PDF file to the victim via browsing or email. The CVSS score is 8.8, and EPSS data is < 1%, but the identified low severity in Chromium’s labeling indicates limited field impact. Nonetheless, the nature of the weakness suggests potential for remote code execution if an attacker can deliver a crafted PDF to the target. No exploitation techniques are published, and the vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread exploitation at present.
OpenCVE Enrichment
Debian DSA