Description
Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Published: 2026-09-09
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a double free in PDFium, the PDF rendering engine used by Google Chrome on Windows. The double free can be triggered by a specially crafted PDF file and can lead to arbitrary code execution inside Chrome’s sandbox process, which may allow the attacker to escape the limited sandbox and compromise the host system.

Affected Systems

Google Chrome running on Windows is affected. Any Windows build of Chrome older than version 153.0.8010.36 contains the flaw; versions 153.0.8010.36 and newer have the fix.

Risk and Exploitability

Chromium labels the issue as high severity, with a CVSS score of 8.8. The exploit is achieved remotely via a malicious PDF, so an attacker may embed the exploit in an email attachment or a malicious website. The double free leads to code execution within the sandboxed renderer; although the sandbox limits the damage, escape remains possible. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, so public exploitation likelihood is uncertain, but the potential impact justifies urgent remediation.

Generated by OpenCVE AI on September 9, 2026 at 19:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later
  • If an update is not feasible, disable Chrome’s built‑in PDF viewer or block PDF rendering for external sites
  • Apply endpoint protection that scans and blocks malicious PDF files before they reach the browser

Generated by OpenCVE AI on September 9, 2026 at 19:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title PDFium Double Free Enables Remote Code Execution in Chrome Windows

Wed, 09 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Microsoft
Microsoft windows

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title PDFium Double Free Enables Remote Code Execution in Chrome Windows

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Weaknesses CWE-415
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:28.039Z

Reserved: 2026-09-08T22:41:29.513Z

Link: CVE-2026-87585

cve-icon Vulnrichment

Updated: 2026-09-09T12:50:51.416Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:16.357

Modified: 2026-09-10T04:18:27.363

Link: CVE-2026-87585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:00:13Z

Weaknesses