Impact
A heap buffer overflow exists in the PDF rendering component of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox by delivering a specially crafted PDF file. The vulnerability is identified as both a heap buffer overflow (CWE-122) and an adjacent buffer overflow (CWE-787) and carries a Chromium severity of High.
Affected Systems
Google Chrome browsers prior to version 147.0.7727.101 are affected. The issue is limited to the PDFium rendering engine used for processing PDF files within the Chrome browser.
Risk and Exploitability
The flaw can be triggered by a PDF file that an untrusted user opens in Chrome, which can lead to arbitrary code execution with at least the privileges of the sandboxed browser process. The CVSS v3.1 score is 8.8, indicating a high severity. No publicly available exploit code is yet reported, and the vulnerability is not listed in the CISA KEV catalog. The risk remains high due to the local file-based nature of the trigger and the ability to run arbitrary code within the sandbox.
OpenCVE Enrichment
Debian DSA