
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5889 is a cryptographic flaw in PDFium, the PDF rendering library embedded in Google Chrome, that allows an attacker to read potentially sensitive information from encrypted PDFs via a brute-force attack. The vulnerability was reported by researcher "mlafon" on February 23, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-326 (Inadequate Encryption Strength), meaning PDFium's implementation of PDF encryption uses a cryptographic scheme that is insufficiently strong to resist brute-force attacks. The attack vector is network-based and requires user interaction — an attacker would need to deliver a specially crafted encrypted PDF to a victim who opens it in Chrome. The weakness likely relates to PDFium's support for legacy PDF encryption standards (e.g., RC4-based or weak AES key derivation), which are susceptible to offline brute-force or dictionary attacks against the encryption key or password. The Chromium issue tracker entry (ID 486906037) is currently restricted pending broad user update (Chrome Releases, GitHub Advisory).
Successful exploitation allows an attacker to read potentially sensitive information contained within encrypted PDF documents opened in a vulnerable version of Chrome. The confidentiality impact is rated Low, with no integrity or availability impact, meaning the attacker cannot modify data or disrupt service — only read protected content. Depending on the sensitivity of the PDF content (e.g., financial records, legal documents, credentials), the disclosure could be significant for targeted individuals or organizations (GitHub Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users should update Google Chrome to version 147.0.7727.55 or later immediately, and ensure automatic updates are enabled. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a precautionary measure, organizations relying on encrypted PDFs for sensitive data protection should review whether those PDFs use strong encryption standards independent of Chrome's rendering (Chrome Releases, Microsoft MSRC).
Security news outlets including GBHackers and CyberSecurityNews covered this vulnerability as part of broader reporting on the Chrome 147 update, which patched over 60 vulnerabilities including two critical WebML flaws. The PDFium cryptographic flaw received moderate attention given its Medium severity rating and lack of active exploitation. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-5889 has been identified beyond standard vulnerability aggregation coverage (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."