CVE-2026-11305

Google · Chrome

A Use-After-Free vulnerability exists in the PDFium library within Google Chrome prior to version 149, potentially allowing for remote code execution.

Executive summary

A critical Use-After-Free memory vulnerability in Google Chrome’s PDFium component requires immediate patching to prevent remote code execution.

Vulnerability

The vulnerability is a Use-After-Free error in the PDFium library. It occurs when the browser improperly handles object memory, allowing an unauthenticated attacker to execute code by convincing a user to open a malicious PDF.

Business impact

With a CVSS score of 8.8, this vulnerability carries a high risk of system compromise. Successful exploitation could result in the total loss of confidentiality, integrity, and availability of the affected workstation.

Remediation

Immediate Action: Update all Google Chrome installations to version 149 or later to incorporate the necessary security patches.

Proactive Monitoring: Monitor for signs of browser instability or unauthorized file system access originating from the Chrome process.

Compensating Controls: Use endpoint detection and response (EDR) solutions to identify and block suspicious shellcode execution triggered by browser processes.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Security teams should treat this as a high-priority update. Given the prevalence of PDF-based attacks, ensuring that the browser engine is fully patched is a fundamental requirement for maintaining a secure computing environment.