Impact
A heap buffer overflow exists within the PDFium component of Google Chrome, allowing a crafted PDF file to trigger an out‑of‑bounds memory write. This flaw can give a remote attacker the ability to alter program flow and potentially execute arbitrary code in the context of the browser process.
Affected Systems
The vulnerability affects Google Chrome releases prior to version 145.0.7632.109. Users running any earlier Chrome build on Windows, macOS, or Linux are potentially exposed.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity, but the EPSS score of less than 1% suggests a low probability of exploitation at this time. It is not listed in CISA’s KEV catalog. Attackers would likely deliver malicious PDF content via email attachments or web downloads, exploiting the PDF viewer to initiate the buffer overflow.
OpenCVE Enrichment
Debian DSA