Description
Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Published: 2026-06-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in Google Chrome’s PDF rendering engine for versions before 149.0.7827.103. When a maliciously crafted PDF file is processed, the memory management bug can be triggered to execute arbitrary code within the sandboxed renderer process. The primary outcome is that an attacker can run code at the renderer level, potentially bypassing the sandbox if additional exploitation steps succeed. The weakness is classified as CWE‑416 and exhibits characteristics of CWE‑825.

Affected Systems

The vulnerability affects the Google Chrome web browser running on any operating system where the PDF viewer component is enabled, specifically for all Chrome releases prior to 149.0.7827.103. Versions equal to or newer than 149.0.7827.103 contain the patch that eliminates the use‑after‑free condition.

Risk and Exploitability

The CVE is rated as High severity (CVSS 8.8) by Chromium’s internal severity model. Because the EPSS data is < 1%, the exact exploitation probability cannot be quantified, but the lack of listing in the CISA KEV catalog implies no publicly identified exploits at this time. The attack vector is remote, requiring only that an attacker provides a malicious PDF to the victim, either via a downloaded file or a link. If the victim opens the file, the exploit can trigger immediately, making the risk significant for users who routinely view PDFs from untrusted sources.

Generated by OpenCVE AI on June 11, 2026 at 01:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.103 or later to apply the repository patch
  • If an upgrade is not immediately possible, disable the built‑in PDF viewer or configure Chrome to block untrusted PDF files from opening
  • Regularly monitor Chrome release notes and automate updates to ensure vulnerability patches are applied promptly

Generated by OpenCVE AI on June 11, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6337-1 chromium security update
History

Thu, 11 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Use after free in PDF
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Tue, 09 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Tue, 09 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDF Rendering Allows Remote Code Execution in Chrome

Tue, 09 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 09 Jun 2026 01:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDF Rendering Allows Remote Code Execution in Chrome
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 08 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-09T03:55:47.232Z

Reserved: 2026-06-08T21:33:47.223Z

Link: CVE-2026-11670

cve-icon Vulnrichment

Updated: 2026-06-09T01:04:02.872Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-09T00:16:50.220

Modified: 2026-06-09T14:53:48.220

Link: CVE-2026-11670

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-08T00:00:00Z

Links: CVE-2026-11670 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T01:45:06Z

Weaknesses