Impact
A use‑after‑free bug in the PDF parser of Google Chrome prior to version 152.0.7977.65 allows a malicious PDF file to trigger execution of arbitrary code within the browser’s sandbox. The vulnerability was rated low by Chromium’s internal severity metrics, but because it can lead to code execution, it is a critical security hazard for users who open untrusted PDF documents with Chrome.
Affected Systems
The flaw affects Google Chrome on desktop platforms when a version earlier than 152.0.7977.65 is installed. Users who have not updated to the listed stable‑channel patch are vulnerable. No specific operating systems are highlighted, so the issue applies to all OSes supported by Chrome.
Risk and Exploitability
The CVSS score is 8.8 and EPSS data is unavailable, so the exact likelihood cannot be quantified. The vulnerability is not in the CISA KEV catalog, yet its nature is a classic, high‑impact use‑after‑free that can be triggered by a crafted PDF delivered via email, web download, or local file. The likely attack vector is a user opening a malicious PDF, so the exploitation requires user interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA