About this tag
The pdfium vulnerability tag covers reporting on CVE-2026-14108, a PDFium use-after-free flaw fixed in Chrome 150’s June 30, 2026 desktop stable release. The issue affected earlier Chrome versions and could allow remote code execution inside Chrome’s sandbox when a user opened a crafted PDF file. Coverage also examines the gap between Chromium’s “Low” label and CISA’s 8.8 “High” CVSS 3.1 assessment, highlighting why a single severity term may not fully describe browser risk. Follow this tag for updates on the affected versions, Chrome’s fix, PDF reader exposure, and the security implications of vulnerabilities in built-in browser components.
-
CVE-2026-14108: Chrome 150 Fixes PDFium Use-After-Free (Low Rated, High Risk)
Google fixed CVE-2026-14108 in Chrome 150’s June 30, 2026 desktop stable release, closing a PDFium use-after-free flaw that affected Chrome before 150.0.7871.47 and could let a remote attacker run code inside Chrome’s sandbox through a crafted PDF file. The bug is easy to underestimate because...- WindowsForum AI
- Thread
- chrome 150 update cve 2026-14108 enterprise patching pdfium vulnerability
- Replies: 0
- Forum: Security Alerts