CVE-2026-17875

Google · Chrome

A use after free vulnerability exists in the PDFium component of Google Chrome, potentially allowing for arbitrary code execution.

Executive summary

A high severity use after free vulnerability in the Google Chrome PDFium component could allow an unauthenticated attacker to execute arbitrary code via a specially crafted PDF document.

Vulnerability

This is a use after free vulnerability located in the PDFium library, which handles PDF rendering within Chrome. The exploit requires a user to open a malicious PDF file, but does not require the attacker to have authenticated access.

Business impact

The CVSS score of 8.8 highlights the severity of this issue, as it permits an attacker to achieve remote code execution through common browser interactions. Successful exploitation could result in full system compromise, causing extensive damage to data security and operational integrity.

Remediation

Immediate Action: Update all Google Chrome deployments to the latest available version to address the vulnerability within the PDFium rendering engine.

Proactive Monitoring: Monitor for suspicious file downloads and unexpected behavior when users interact with PDF content within the browser.

Compensating Controls: Implement robust email and web filtering to prevent the delivery of malicious PDF files and ensure that endpoint detection and response tools are active.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize the deployment of the provided security updates to address this PDFium vulnerability. Ensuring all browser instances are running the patched version is the most effective way to eliminate this risk.