CVE-2026-93381
8.8Google · Chrome
A buffer overflow vulnerability in the PDFium component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a specially crafted PDF file.
Executive summary
A critical buffer overflow vulnerability in Google Chrome for Windows could allow a remote attacker to execute arbitrary code on an end user system.
Vulnerability
This flaw is a buffer overflow (CWE-122) within the PDFium library. An unauthenticated remote attacker can trigger this vulnerability by tricking a user into opening a malicious PDF file, which subsequently leads to arbitrary code execution within the browser sandbox.
Business impact
Successful exploitation poses a significant risk to organizational endpoints, as it allows for unauthorized code execution and potential system compromise. With a CVSS score of 8.8, this high severity vulnerability necessitates immediate attention to prevent potential data theft or the deployment of secondary malware payloads on corporate workstations.
Remediation
Immediate Action: Update Google Chrome to version 153.0.8010.52 or later across all Windows-based assets immediately.
Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process execution patterns following the viewing of PDF documents.
Compensating Controls: Deploy endpoint protection platforms that utilize heuristic analysis to detect and block malicious PDF files or sandbox-escaping attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution, organizations must prioritize the deployment of the Chrome update to all affected Windows systems. Ensure that automated update mechanisms are functioning correctly to mitigate the risk of exploitation.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section