Description
Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Published: 2026-06-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in Google Chrome’s PDF rendering engine for versions before 149.0.7827.103. When a maliciously crafted PDF file is processed, the memory management bug can be triggered to execute arbitrary code within the sandboxed renderer process. The primary outcome is that an attacker can run code at the renderer level, potentially bypassing the sandbox if additional exploitation steps succeed. The weakness is classified as CWE‑416.

Affected Systems

The vulnerability affects the Google Chrome web browser running on any operating system where the PDF viewer component is enabled, specifically for all Chrome releases prior to 149.0.7827.103. Versions equal to or newer than 149.0.7827.103 contain the patch that eliminates the use‑after‑free condition.

Risk and Exploitability

The CVE is rated as High severity (CVSS 8.8) by Chromium’s internal severity model. Because the EPSS data is not available, the exact exploitation probability cannot be quantified, but the lack of listing in the CISA KEV catalog implies no publicly identified exploits at this time. The attack vector is remote, requiring only that an attacker provides a malicious PDF to the victim, either via a downloaded file or a link. If the victim opens the file, the exploit can trigger immediately, making the risk significant for users who routinely view PDFs from untrusted sources.

Generated by OpenCVE AI on June 9, 2026 at 02:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.103 or later to apply the repository patch
  • If an upgrade is not immediately possible, disable the built‑in PDF viewer or configure Chrome to block untrusted PDF files from opening
  • Regularly monitor Chrome release notes and automate updates to ensure vulnerability patches are applied promptly

Generated by OpenCVE AI on June 9, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Tue, 09 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDF Rendering Allows Remote Code Execution in Chrome

Tue, 09 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 09 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDF Rendering Allows Remote Code Execution in Chrome
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-09T03:55:47.232Z

Reserved: 2026-06-08T21:33:47.223Z

Link: CVE-2026-11670

cve-icon Vulnrichment

Updated: 2026-06-09T01:04:02.872Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T00:16:50.220

Modified: 2026-06-09T14:53:48.220

Link: CVE-2026-11670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T03:00:14Z

Weaknesses