Description
Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in PDFium, the PDF rendering component used by Google Chrome. A maliciously crafted PDF can trigger the flaw and allow an attacker to execute arbitrary code inside Chrome’s sandboxed processes, leading to remote code execution. The weakness is classified as CWE‑416.

Affected Systems

Google Chrome versions released before 150.0.7871.47 on the stable channel are vulnerable; versions 150.0.7871.47 and later include the fix.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity risk, while the EPSS score of <1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to deliver a crafted PDF; the likely attack vector is via e‑mail attachment or a malicious website, to exploit the use‑after‑free condition.

Generated by OpenCVE AI on July 17, 2026 at 13:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to apply the PDFium fix.
  • If upgrading is not immediately possible, disable PDFium handling via Chrome policies or settings to block PDF parsing.
  • Maintain operating‑system and sandboxing features to contain any accidental privilege escalation attempts.
  • Check the Chromium project website or Chrome release notes regularly for updates or additional mitigations.

Generated by OpenCVE AI on July 17, 2026 at 13:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Chrome PDFium Use‑After‑Free Remote Code Execution

Wed, 15 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Use-After-Use Free in PDFium Enables Remote Code Execution in Google Chrome

Tue, 14 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Use-After-Use Free in PDFium Enables Remote Code Execution in Google Chrome

Sun, 12 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in PDFium Enables Remote Code Execution via Crafted PDF

Sat, 11 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in PDFium Enables Remote Code Execution via Crafted PDF

Fri, 10 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in PDFium Enables Remote Code Execution via Crafted PDF

Thu, 09 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in PDFium Enables Remote Code Execution via Crafted PDF

Wed, 08 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDFium Allows Remote Code Execution in Chrome

Wed, 08 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDFium Allows Remote Code Execution in Chrome

Tue, 07 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Use-After‑Free in PDFium Allows Remote Code Execution via Crafted PDF in Chrome

Mon, 06 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Use-After‑Free in PDFium Allows Remote Code Execution via Crafted PDF in Chrome

Mon, 06 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDFium Enables Remote Code Execution in Chrome

Sun, 05 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDFium Enables Remote Code Execution in Chrome

Sun, 05 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in PDFium Allows Remote Code Execution in Chrome

Sat, 04 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in PDFium Allows Remote Code Execution in Chrome

Fri, 03 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome PDFium Enables Remote Code Execution

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome PDFium Enables Remote Code Execution

Thu, 02 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome PDF Engine Enables Sandbox Code Execution

Thu, 02 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome PDF Engine Enables Sandbox Code Execution

Thu, 02 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDFium Allows Remote Code Execution in Chrome

Thu, 02 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDFium Allows Remote Code Execution in Chrome

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDFium Enables Sandbox Code Execution

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in PDFium Enables Sandbox Code Execution

Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Use After Free in PDFium Enables Remote Code Execution in Google Chrome

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Use After Free in PDFium Enables Remote Code Execution in Google Chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:19.166Z

Reserved: 2026-06-29T23:11:43.809Z

Link: CVE-2026-14108

cve-icon Vulnrichment

Updated: 2026-07-01T13:59:53.881Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T13:45:05Z

Weaknesses