Description
Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High)
Published: 2026-05-28
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow in PDFium enables a remote attacker who has already compromised the renderer process to execute arbitrary code inside the Chrome sandbox. The flaw is a classic CWE‑472 situation where miscalculated lengths during font parsing can trigger overflow conditions that bypass memory boundaries. The impact is therefore a full code‑execution privilege escalation within the limited renderer context, which can ultimately lead to system compromise if the sandbox is circumvented or malicious payloads are injected. The vulnerability is rated high severity by Chromium security.

Affected Systems

Google Chrome browsers on any platform that are running a version earlier than 148.0.7778.216 are affected. The issue is tied to the PDFium component used for rendering PDF and font files. All users of the stable channel of Chrome before the referenced update are potentially vulnerable.

Risk and Exploitability

Exploitability details are quantifiable; the EPSS score is 0.0008, indicating a very low probability that this vulnerability will be leveraged in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack requires that a compromised renderer process be triggered, which typically occurs via a malicious font embedded in a PDF or web page. Therefore, an attacker must first deliver a crafted payload to the user and rely on Chrome’s standard sandboxing. The risk remains high because the vulnerability can lead to arbitrary code execution even within the restricted sandbox, and no remediation is available other than updating the browser. The CVSS score of 7.5 indicates high severity. The likely attack path is through PDF rendering with a crafted font, inferred from the description of the integer overflow.

Generated by OpenCVE AI on May 29, 2026 at 15:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 148.0.7778.216 or newer to apply the PDFium integer‑overflow fix.
  • If upgrading is delayed, disable PDF rendering in Chrome via policy settings or service workers that consume PDF files to mitigate exposure.
  • Ensure Chrome’s sandboxing features are enabled and that the operating system’s security updates are current so that any escape from the sandbox is minimized.

Generated by OpenCVE AI on May 29, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Remote code execution via PDFium integer overflow chromium-browser: Integer overflow in PDFium
Weaknesses CWE-190
References
Metrics threat_severity

None

threat_severity

Important


Fri, 29 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 29 May 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 29 May 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote code execution via PDFium integer overflow

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T10:59:22.413Z

Reserved: 2026-05-28T17:25:01.011Z

Link: CVE-2026-9960

cve-icon Vulnrichment

Updated: 2026-05-29T10:53:42.557Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:54.213

Modified: 2026-05-29T16:18:15.647

Link: CVE-2026-9960

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9960 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T15:30:04Z

Weaknesses