CVE-2026-87585
8.8Google · Chrome
A double free vulnerability in the PDFium component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a malicious PDF file.
Executive summary
A high-severity double free vulnerability in Google Chrome for Windows allows unauthenticated remote attackers to achieve arbitrary code execution through crafted PDF documents.
Vulnerability
This flaw is a double free memory corruption vulnerability (CWE-415) residing in the PDFium library. An unauthenticated remote attacker can trigger this condition by enticing a user to open a specially crafted PDF file, potentially leading to code execution within the browser sandbox.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational endpoints, as it allows for arbitrary code execution. Given the CVSS score of 8.8, this flaw represents a significant threat to confidentiality, integrity, and availability. Compromised browsers may serve as an entry point for lateral movement or the deployment of additional malware within the corporate network.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.36 or later across all Windows workstations immediately.
Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected child process spawning associated with the Chrome PDFium renderer.
Compensating Controls: Deploy endpoint protection solutions that include exploit prevention features to detect memory corruption attempts, and consider restricting the opening of untrusted PDF files.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
This vulnerability presents a high risk due to the potential for remote code execution via common user interaction. IT administrators must prioritize the deployment of the provided security update to ensure all Chrome instances are running version 153.0.8010.36 or newer. Timely patching is the most effective defense against this class of memory-based attacks.
More Google CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- Analyst report written
- Published in the daily brief high section