ZeroHour

CVE-2026-93381

mass

Buffer Overflow in Google Chrome PDFium on Windows via Crafted PDF Files

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-93381 is a buffer overflow (CWE-122) in the PDFium PDF rendering engine of Google Chrome on Windows. To trigger it, an attacker must use social engineering to convince a user to open a specially crafted PDF file, which causes the overflow in Chrome's PDF renderer. Successful exploitation could allow a remote attacker to execute arbitrary code, though only inside Chrome's sandbox, which constrains the impact of the compromise. All Chrome users on Windows running versions prior to 153.0.8010.52 are affected; users on other operating systems are not impacted by this specific flaw. There is currently no CVSS score, no entry in the CISA KEV catalog, no known public proof-of-concept, and no confirmed exploitation in the wild, and the fix shipped in Chrome 153.0.8010.52 alongside roughly 15 other security fixes, including two rated critical.

What to do: Update Google Chrome on Windows to 153.0.8010.52 or later (Help > About Google Chrome, or enforce via endpoint management) and verify deployed versions with your fleet inventory tools. Until patched, caution users against opening PDFs from untrusted or unexpected sources, since exploitation depends on social engineering. Prioritize the update, as the same Chrome 153 release also addresses two critical vulnerabilities.

Affected
Google Chrome (PDFium component)Windows versions prior to 153.0.8010.52
Estimated exposure
mass≈3 billion+ Chrome users worldwide, with the Windows desktop subset affected (likely well over 1 billion installations) — Chrome holds roughly 65% of global browser market share with more than 3 billion users, and since this flaw affects only the Windows build, the affected install base is still the Windows portion of that very large population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)

Weakness
CWE-122
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.