CVE-2026-2648
8.8Google · Chrome
A heap buffer overflow in the PDFium component of Google Chrome allows remote attackers to perform out of bounds memory writes via crafted PDF files.
Executive summary
Google Chrome versions prior to 145.0.7632.109 are vulnerable to a heap buffer overflow in the PDFium engine, which could allow a remote attacker to achieve arbitrary code execution.
Vulnerability
This is a heap buffer overflow vulnerability (CWE-122) within the PDFium library. The flaw is exploitable by an unauthenticated remote attacker through the delivery of a specially crafted PDF file that triggers an out of bounds memory write when processed by the browser.
Business impact
Successful exploitation of this vulnerability allows for memory corruption, which typically leads to arbitrary code execution or application crashes. Given the CVSS score of 8.8, this represents a high risk to organizational security, as it could facilitate the installation of malware or the theft of sensitive user data if a user is enticed to open a malicious PDF document.
Remediation
Immediate Action: Update all Google Chrome installations to version 145.0.7632.109 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for unexpected browser crashes or suspicious process spawning associated with the Chrome PDFium renderer.
Compensating Controls: Deploy browser-based security policies that restrict the automatic execution of PDF content or utilize endpoint protection platforms to detect malicious file signatures.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
This vulnerability presents a significant risk to end-user workstations due to the ubiquity of PDF handling in modern business workflows. Administrators should prioritize the deployment of the Chrome update to all managed environments to eliminate the risk of remote code execution via malicious PDF content.