CVE-2026-18012
Google · Chrome
A use after free vulnerability exists in the PDFium component of Google Chrome, which may allow a remote attacker to execute arbitrary code.
Executive summary
A critical use after free vulnerability in the PDFium component of Google Chrome presents a significant risk of arbitrary code execution.
Vulnerability
This vulnerability is a use after free flaw (CWE-416) located within the PDFium library. It can be exploited by an unauthenticated attacker through the delivery of a specially crafted PDF document, requiring user interaction to trigger the vulnerability.
Business impact
With a CVSS score of 8.8, this vulnerability is considered high risk. Successful exploitation could allow an attacker to bypass security controls, leading to unauthorized access to sensitive information or the execution of malicious payloads, which could compromise the stability and security of the host environment.
Remediation
Immediate Action: Update Google Chrome to the latest version immediately to patch the PDFium component.
Proactive Monitoring: Review security logs for irregular browser behavior and monitor systems for unexpected process crashes related to PDF document rendering.
Compensating Controls: Utilize endpoint protection software that can detect and block malicious PDF files or browser-based exploits at the network or host level.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates immediate action to update all affected Chrome installations. Organizations should ensure that automated update mechanisms are functioning correctly to minimize the window of exposure to this threat.