Impact
The vulnerability is a use‑after‑free in PDFium, the PDF renderer used by Google Chrome. An attacker can craft a malicious PDF that triggers the freed memory bug, allowing execution of arbitrary code. The code runs inside the Chrome sandbox, potentially allowing the attacker to compromise the host or gain elevated privileges. This weakness is identified as CWE‑416 and is considered low severity by Chromium's security team.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 on all supported operating systems that enable the built‑in PDF viewer are affected. Any system that processes untrusted PDF files with a vulnerable Chrome build is at risk.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not provided, but the description indicates a remote use‑after‑free that can be triggered by opening a malicious PDF. The likelihood of exploitation remains uncertain due to a lack of publicly known exploits, yet the remote code execution nature demands timely mitigation.
OpenCVE Enrichment