CVE-2026-11305
Google · Chrome
A Use-After-Free vulnerability exists in the PDFium library within Google Chrome prior to version 149, potentially allowing for remote code execution.
Executive summary
A critical Use-After-Free memory vulnerability in Google Chrome’s PDFium component requires immediate patching to prevent remote code execution.
Vulnerability
The vulnerability is a Use-After-Free error in the PDFium library. It occurs when the browser improperly handles object memory, allowing an unauthenticated attacker to execute code by convincing a user to open a malicious PDF.
Business impact
With a CVSS score of 8.8, this vulnerability carries a high risk of system compromise. Successful exploitation could result in the total loss of confidentiality, integrity, and availability of the affected workstation.
Remediation
Immediate Action: Update all Google Chrome installations to version 149 or later to incorporate the necessary security patches.
Proactive Monitoring: Monitor for signs of browser instability or unauthorized file system access originating from the Chrome process.
Compensating Controls: Use endpoint detection and response (EDR) solutions to identify and block suspicious shellcode execution triggered by browser processes.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Security teams should treat this as a high-priority update. Given the prevalence of PDF-based attacks, ensuring that the browser engine is fully patched is a fundamental requirement for maintaining a secure computing environment.