CVE-2026-93382
8.8Google · Chrome
A use after free vulnerability exists in the PDFium component of Google Chrome, allowing a remote attacker to execute arbitrary code via a crafted HTML page.
Executive summary
Google Chrome versions prior to 153.0.8010.52 contain a critical use after free vulnerability in the PDFium library that allows remote code execution.
Vulnerability
This vulnerability is a use after free flaw (CWE-416) within the PDFium engine. An unauthenticated remote attacker can trigger this memory corruption by enticing a user to view a specially crafted HTML page, potentially leading to arbitrary code execution within the browser sandbox.
Business impact
Successful exploitation allows an attacker to execute arbitrary code on the host machine, which may lead to complete system compromise or data exfiltration. With a CVSS score of 8.8, this vulnerability represents a high-severity risk that could facilitate malware delivery or unauthorized access to sensitive user information stored within the browser environment.
Remediation
Immediate Action: Update all Google Chrome installations to version 153.0.8010.52 or later to apply the necessary security patches.
Proactive Monitoring: Monitor endpoint logs for abnormal browser process behavior or crashes related to the PDFium rendering engine.
Compensating Controls: Ensure that browser security features like site isolation remain enabled, as these can provide defense in depth against sandbox escape attempts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability, organizations should prioritize the deployment of the latest Chrome update across all managed workstations. Failure to patch may expose users to browser-based exploitation that bypasses traditional perimeter security controls.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
- Published in the daily brief high section