What the vulnerability does

01Description

Heap buffer overflow in PDFium in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

Key dates

02Disclosure timeline

March 20, 2026 CVE published
March 21, 2026 Record updated