Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- >= 130, < 134.0.6998.35
A medium-severity out-of-bounds read vulnerability has been identified in the PDFium library used by Google Chrome. This issue affects Chrome versions prior to 134.0.6998.35. The vulnerability allows remote attackers to potentially access memory out of the intended bounds by exploiting a crafted PDF file.
Exploitation of this vulnerability could lead to a memory access violation, causing a crash or potentially allowing for arbitrary code execution.
The vulnerability can be reproduced by downloading the latest AddressSanitizer (ASan) build of Chrome, and then running it with the 'no-sandbox' option. A crafted PDF file must be served via a local web server and accessed by the Chrome instance.
Users should update to Google Chrome version 134.0.6998.35 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.