CVE-2026-5889
vulnerability analysis and mitigation

Overview

CVE-2026-5889 is a cryptographic flaw in PDFium, the PDF rendering library embedded in Google Chrome, that allows an attacker to read potentially sensitive information from encrypted PDFs via a brute-force attack. The vulnerability was reported by researcher "mlafon" on February 23, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The root cause is classified as CWE-326 (Inadequate Encryption Strength), meaning PDFium's implementation of PDF encryption uses a cryptographic scheme that is insufficiently strong to resist brute-force attacks. The attack vector is network-based and requires user interaction — an attacker would need to deliver a specially crafted encrypted PDF to a victim who opens it in Chrome. The weakness likely relates to PDFium's support for legacy PDF encryption standards (e.g., RC4-based or weak AES key derivation), which are susceptible to offline brute-force or dictionary attacks against the encryption key or password. The Chromium issue tracker entry (ID 486906037) is currently restricted pending broad user update (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows an attacker to read potentially sensitive information contained within encrypted PDF documents opened in a vulnerable version of Chrome. The confidentiality impact is rated Low, with no integrity or availability impact, meaning the attacker cannot modify data or disrupt service — only read protected content. Depending on the sensitivity of the PDF content (e.g., financial records, legal documents, credentials), the disclosure could be significant for targeted individuals or organizations (GitHub Advisory, Chrome Releases).

Exploitation steps

  1. Craft a malicious encrypted PDF: An attacker creates or obtains an encrypted PDF document that leverages weak encryption parameters supported by PDFium (e.g., 40-bit RC4 or weak password-based key derivation).
  2. Deliver the PDF to the victim: The attacker distributes the PDF via email, a malicious website, or a file-sharing platform, enticing the victim to open it in a vulnerable version of Google Chrome (prior to 147.0.7727.55).
  3. Victim opens the PDF: Chrome's PDFium renderer processes the encrypted PDF, exposing the weak cryptographic parameters or encrypted content to the attacker (e.g., via a network-accessible resource or exfiltration mechanism).
  4. Brute-force the encryption: The attacker applies offline brute-force or dictionary attack tools against the captured encrypted PDF data, exploiting the inadequate encryption strength to recover the plaintext content.
  5. Read sensitive information: The attacker decrypts and reads the previously protected PDF content (Chrome Releases, GitHub Advisory).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users should update Google Chrome to version 147.0.7727.55 or later immediately, and ensure automatic updates are enabled. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a precautionary measure, organizations relying on encrypted PDFs for sensitive data protection should review whether those PDFs use strong encryption standards independent of Chrome's rendering (Chrome Releases, Microsoft MSRC).

Community reactions

Security news outlets including GBHackers and CyberSecurityNews covered this vulnerability as part of broader reporting on the Chrome 147 update, which patched over 60 vulnerabilities including two critical WebML flaws. The PDFium cryptographic flaw received moderate attention given its Medium severity rating and lack of active exploitation. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-5889 has been identified beyond standard vulnerability aggregation coverage (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management