Impact
The vulnerability is a use‑after‑free in PDFium, the PDF renderer used by Google Chrome. An attacker can craft a malicious PDF that triggers the freed memory bug, allowing execution of arbitrary code. The code runs inside the Chrome sandbox, potentially allowing the attacker to compromise the host or gain elevated privileges. This weakness is identified as CWE‑825.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 on all supported operating systems that enable the built‑in PDF viewer are affected. Any system that processes untrusted PDF files with a vulnerable Chrome build is at risk.
Risk and Exploitability
The EPSS score is 0.0008, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 8.8, indicating a high severity. The description indicates a remote use‑after‑free that can be triggered by opening a malicious PDF. The likelihood of exploitation remains uncertain due to a lack of publicly known exploits, yet the remote code execution nature demands timely mitigation.
OpenCVE Enrichment
Debian DSA