Impact
A use‑after‑free flaw in Chrome's PDF rendering engine (PDFium) permits an attacker to craft a malicious PDF that, when opened, triggers arbitrary code execution inside the Chrome sandbox. The vulnerability aligns with CWE‑416 and enables a remote attacker to run code within the process context that otherwise would have been restricted by the sandbox, effectively jeopardizing the integrity and confidentiality of the user's environment.
Affected Systems
Google Chrome desktop versions prior to 149.0.7827.53 are affected. No other products or version ranges are listed.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity vulnerability, and no EPSS value is provided, so exploitation probability remains uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation. Attackers must deliver a specially crafted PDF to the victim, who then opens it. If leveraged, code execution would occur within the Chrome sandbox but still represent a significant local privilege escalation. Without a publicly available exploit and considering Chromium's internal low severity classification, the attack likelihood appears modest.
OpenCVE Enrichment