CVE-2026-9958
8.8Google · Chrome
A use-after-free vulnerability in the PDFium component of Google Chrome allows remote attackers to trigger memory corruption and potentially execute arbitrary code.
Executive summary
Google Chrome versions prior to 148 are vulnerable to a use-after-free defect in the PDFium library that could lead to remote code execution.
Vulnerability
This is a use-after-free vulnerability within PDFium, the library Chrome uses to render PDF documents. An attacker can exploit this by enticing a user to open a maliciously crafted PDF file, potentially resulting in unauthorized code execution.
Business impact
PDF-based attacks are a common vector for initial access and malware delivery. The CVSS score of 8.8 underscores the danger of this vulnerability, which could lead to a compromise of the workstation if a user interacts with a malicious document.
Remediation
Immediate Action: Update all Google Chrome instances to version 148.0.7778.216 or later to patch the PDFium library.
Proactive Monitoring: Monitor for unexpected downloads or the opening of PDF files from untrusted sources within the organization.
Compensating Controls: Use browser-based security policies to disable PDF rendering within the browser if the business use case allows, or utilize a sandbox-enabled PDF viewer.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the prevalence of PDF documents in business workflows, this vulnerability presents an elevated risk. It is imperative to roll out the latest Chrome security updates to all users to prevent potential exploitation via malicious PDF content.