
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2648 is a heap buffer overflow vulnerability in the PDFium PDF rendering engine used by Google Chrome, allowing a remote attacker to perform an out-of-bounds memory write via a crafted PDF file. It was reported by researcher "soiax" on January 19, 2026, and publicly disclosed on February 18, 2026, when Google released Chrome 145.0.7632.109. Affected products include Google Chrome prior to version 145.0.7632.109 and Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow) and resides in Chrome's PDFium component, the library responsible for rendering PDF files. When a user opens a specially crafted PDF file, insufficient bounds checking in PDFium allows an attacker to write data beyond the allocated heap buffer boundaries. Exploitation requires user interaction — specifically, the victim must open a malicious PDF file — but no authentication or elevated privileges are required on the attacker's side. The bug was tracked internally as Chromium issue 477033835 (Chrome Releases).
Successful exploitation of this vulnerability could allow a remote attacker to achieve arbitrary code execution with the privileges of the Chrome browser process, potentially leading to full compromise of the affected system's confidentiality, integrity, and availability. An attacker could leverage this to steal sensitive data, install malware, or pivot to other systems accessible from the compromised host. The impact is scoped to the Chrome process sandbox, though sandbox escapes in combination with other vulnerabilities could extend the reach further (Chrome Releases).
cmd.exe, powershell.exe, bash, curl, or wget); Chrome processes consuming abnormally high memory after opening a PDF.Google has released a patch in Chrome version 145.0.7632.109 (Linux) and 145.0.7632.109/110 (Windows/Mac), which addresses this vulnerability. Microsoft has also released a corresponding update for Edge (Chromium-based). Users and administrators should immediately update Chrome to version 145.0.7632.109 or later via the browser's built-in update mechanism or enterprise deployment tools. As an interim workaround prior to patching, users should avoid opening PDF files from untrusted sources directly in Chrome, and organizations may consider enforcing PDF handling through dedicated, sandboxed PDF readers (Chrome Releases, Microsoft MSRC).
The vulnerability received broad coverage from cybersecurity news outlets, with multiple sources characterizing the Chrome update as an "emergency" or "urgent" patch given the High severity rating and the co-disclosure of additional flaws (CVE-2026-2649, CVE-2026-2650). Security news sites including CyberSecurityNews, GBHackers, and SecurityOnline.info highlighted the PDFium and V8 flaws together, urging immediate updates. Notably, NotebookCheck reported that exploit code for related Chrome vulnerabilities went public around the same time, adding urgency to the patching recommendation. Downstream Linux distributions including Debian, openSUSE, and Fedora also issued Chromium security advisories addressing this CVE (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."