Impact
A buffer overflow flaw exists in the PDF rendering engine PDFium used by Google Chrome on Windows machines prior to version 153.0.8010.52. The vulnerability allows a malicious PDF file to corrupt memory while parsing, which an attacker could exploit to run arbitrary code inside the sandbox. This defeats sandbox boundaries and could lead to full system compromise if the attacker succeeds.
Affected Systems
Google Chrome running on Windows operating systems below version 153.0.8010.52 is affected. This includes all Chrome installations that have not yet applied the stable channel security update announced in September 2026.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability, and the EPSS score of less than 1% suggests that exploitation is unlikely at present, though not impossible. The issue is not listed in CISA's KEV catalog, so there are no known large-scale exploit campaigns reported. Remote exploitation would require a social engineering step to get the victim to open a crafted PDF, implying a user‑interaction prerequisite. The flaw could become a vector for remote code execution if attackers successfully persuade users to open malicious files.
OpenCVE Enrichment
Debian DLA
Debian DSA