Heap buffer overflow in PDFium in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
| Vendor | Product | Versions |
|---|---|---|
| chrome | 147.0.7727.101 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apple | macos | cve_cpe | 95% |
| linux | linux_kernel | cve_cpe | 95% |
| microsoft | windows | cve_cpe | 95% |
Updated vendor to Microsoft and product to Edge, marked exploit as available and actively exploited.
Updated severity to CRITICAL, patch available version to 147.0.7727.55, and clarified that no exploit exists.
Initial creation