CVE-2026-93381

8.8

Google · Chrome

A buffer overflow vulnerability in the PDFium component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a specially crafted PDF file.

Executive summary

A critical buffer overflow vulnerability in Google Chrome for Windows could allow a remote attacker to execute arbitrary code on an end user system.

Vulnerability

This flaw is a buffer overflow (CWE-122) within the PDFium library. An unauthenticated remote attacker can trigger this vulnerability by tricking a user into opening a malicious PDF file, which subsequently leads to arbitrary code execution within the browser sandbox.

Business impact

Successful exploitation poses a significant risk to organizational endpoints, as it allows for unauthorized code execution and potential system compromise. With a CVSS score of 8.8, this high severity vulnerability necessitates immediate attention to prevent potential data theft or the deployment of secondary malware payloads on corporate workstations.

Remediation

Immediate Action: Update Google Chrome to version 153.0.8010.52 or later across all Windows-based assets immediately.

Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process execution patterns following the viewing of PDF documents.

Compensating Controls: Deploy endpoint protection platforms that utilize heuristic analysis to detect and block malicious PDF files or sandbox-escaping attempts.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote code execution, organizations must prioritize the deployment of the Chrome update to all affected Windows systems. Ensure that automated update mechanisms are functioning correctly to mitigate the risk of exploitation.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief high section

Sources