CVE-2026-2648: Heap buffer overflow in PDFium
Chromium: CVE-2026-2648 Heap buffer overflow in PDFium
Other sources
Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chromium security severity: High)
— NVD
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-2648?
The severity of CVE-2026-2648 is classified as High.
What are the potential impacts of CVE-2026-2648?
CVE-2026-2648 can allow a remote attacker to perform an out of bounds memory write via a crafted PDF file.
Which versions of Google Chrome are affected by CVE-2026-2648?
Google Chrome versions prior to 145.0.7632.109 are affected by CVE-2026-2648.
How do I fix CVE-2026-2648?
To fix CVE-2026-2648, update Google Chrome to version 145.0.7632.109 or later.
What component of Google Chrome is impacted by CVE-2026-2648?
CVE-2026-2648 impacts the PDFium component within Google Chrome.