Description
Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security severity: Medium)
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Chrome’s PDF a remote attacker to craft a PDF that manipulates the browser’s user interface. When a user opens the malicious file, deceptive controls or messages can appear as authentic UI elements, potentially leading the user to perform unintended actions or disclose sensitive data. The weakness is classified as CWE‑451, indicating that the vulnerability results from manipulating input data. The CVSS score of 6.5 signals a medium severity impact focused on user deception rather than direct code execution or data loss.

Affected Systems

Any installation of Google Chrome that incorporates an unpatched version of PDFium may be affected. The vulnerability exists in builds prior to version 150.0.7871.46; later releases contain the fix. Because the vendor advisory does not enumerate each sub‑release, all Chrome builds before that build number should be treated as vulnerable until the browser receives an updated release.

Risk and Exploitability

Exploitation requires the victim to open a crafted PDF file, so the likely attack vector involves user interaction such as clicking on a malicious link or attaching a file. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalogue. Nevertheless, the moderate CVSS score and potential for social engineering underscore the need for timely remediation through patching.

Generated by OpenCVE AI on July 21, 2026 at 13:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest PDFium security fix.
  • Avoid opening PDF files from untrusted or unknown sources; scan attachments or view them in a sandboxed environment before opening.
  • Disable Chrome’s built‑in PDF viewer and use a separate, secure PDF reader until the official patch is installed.

Generated by OpenCVE AI on July 21, 2026 at 13:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious PDF in Google Chrome

Wed, 15 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious PDF in Google Chrome

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malformed PDF in Chrome PDF Viewer

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malformed PDF in Chrome PDF Viewer

Sun, 12 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability via Malicious PDF in Google Chrome

Sat, 11 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability via Malicious PDF in Google Chrome

Fri, 10 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome PDF UI Spoofing Vulnerability

Thu, 09 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome PDF UI Spoofing Vulnerability

Tue, 07 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Chrome PDFium UI Spoofing Vulnerability

Tue, 07 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chrome PDFium UI Spoofing Vulnerability

Mon, 06 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome PDFium UI Spoofing Vulnerability

Mon, 06 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome PDFium UI Spoofing Vulnerability

Sun, 05 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome PDFium UI Spoofing Vulnerability

Sun, 05 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Chrome PDFium UI Spoofing Vulnerability

Sun, 05 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted PDF in Chrome PDFium

Sat, 04 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted PDF in Chrome PDFium

Sat, 04 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome PDFium

Sat, 04 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome PDFium

Fri, 03 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted PDF in Chrome PDF Renderer

Fri, 03 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted PDF in Chrome PDF Renderer

Fri, 03 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title User Interface Spoofing via Crafted PDF in Chrome

Thu, 02 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title User Interface Spoofing via Crafted PDF in Chrome

Thu, 02 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Chrome PDFium UI Spoofing Vulnerability
Weaknesses CWE-79

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome PDFium UI Spoofing Vulnerability
Weaknesses CWE-79

Thu, 02 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T13:12:41.518Z

Reserved: 2026-07-01T21:37:29.470Z

Link: CVE-2026-14404

cve-icon Vulnrichment

Updated: 2026-07-02T13:12:38.104Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:15:05Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information