CVE-2026-5287

8.8

Google · Chrome

A use-after-free vulnerability in the PDF processing component of Google Chrome allows remote attackers to execute arbitrary code via a crafted PDF file.

Executive summary

A critical use-after-free vulnerability in Google Chrome allows remote code execution, posing a significant risk to user systems.

Vulnerability

This is a use-after-free vulnerability (CWE-416) within the PDF engine of Google Chrome. It can be triggered by an unauthenticated remote attacker when a user opens a specifically crafted PDF file, potentially leading to arbitrary code execution within the browser sandbox.

Business impact

The ability for an attacker to execute arbitrary code on a user workstation presents a severe risk of data breach, malware installation, and lateral movement within the corporate network. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires immediate attention to prevent potential system compromise.

Remediation

Immediate Action: Update all instances of Google Chrome to version 146.0.7680.178 or later immediately.

Proactive Monitoring: Review endpoint security logs for unexpected browser process crashes or anomalous network activity originating from user workstations.

Compensating Controls: Utilize endpoint protection platforms to detect and block the execution of malicious PDF files and restrict the ability of browsers to launch unauthorized child processes.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this vulnerability, combined with the widespread use of Chrome for daily business operations, necessitates an urgent patching cycle. Security teams should prioritize the deployment of the update across all organizational endpoints to eliminate the risk of remote code execution via malicious PDF content.

More Google CVEs

Sources