Impact
In Google Chrome versions prior to 151.0.7922.72, the PDFium component contains a use‑after‑free flaw that permits a remote attacker to execute arbitrary code inside the browser’s sandbox when a specially crafted PDF file is opened. The flaw is a classic use‑after‑free (CWE‑416) with an associated heap corruption component (CWE‑825).
Affected Systems
Google Chrome operating on any platform that is running a version earlier than 151.0.7922.72 is affected.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1 % denotes a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attack requires a user to open a malicious PDF, giving the vector a remote nature via a crafted file. The code runs within the browser’s sandbox; no further exploitation steps are described in the provided data.
OpenCVE Enrichment
Debian DLA
Debian DSA