CVE-2026-93381: Buffer Overflow
Published Sep 17, 2026
·Updated
Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
Affected Software
2 affected components
Google Chrome<153.0.8010.52
Google PDFium
Event History
Sep 17, 2026
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
DescriptionWeakness
Frequently Asked Questions
1
Which systems are affected?
The issue affects Google Chrome on Windows before version 153.0.8010.52. It involves PDFium handling of a crafted PDF file.
2
What does an attacker need to exploit this issue?
An attacker needs to convince a user to interact with a crafted PDF file. Successful exploitation could potentially execute arbitrary code inside the Chrome sandbox.
3
Does this vulnerability allow code execution outside the sandbox?
The available information describes potential arbitrary code execution inside the sandbox only. It does not state that the flaw enables a sandbox escape or execution outside the sandbox.