CVE-2026-9960: Integer overflow in PDFium in Google Chrome prior to 148
Integer overflow in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted font file. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
An integer overflow in PDFium, the PDF rendering library bundled with Google Chrome, allows a remote attacker who has already compromised the renderer process to execute arbitrary code inside the browser sandbox via a crafted font file. The vulnerability is reachable over the network but requires the attacker to have pre-compromised the renderer and to trick a user into interacting with malicious content; successful exploitation gives the attacker code execution within the sandbox. A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-9960 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium. Any image carrying a Chrome version below 148.0.7778.216 is flagged automatically.
AvailableHarborGuard scores this CVE at 7.5 HIGH using the published CVSS v3.1 vector and surfaces it with per-environment compliance policy weighting, so teams running stricter browser-security policies see it elevated in their queue. Findings are routed to the inbox configured for each customer org, ensuring the right team receives the alert without manual filtering.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 becomes available through HarborGuard once the fix version is confirmed against the affected image layer. For customers who opt into auto-remediation, HarborGuard rebuilds the image, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network, delivering a crafted font file through a web page or other network-accessible content.
- AuthenticationNot required
No account or credentials are needed; the attacker operates as an unauthenticated remote party.
- Victim interactionRequired
A user must interact with attacker-controlled content, such as opening a malicious PDF or visiting a crafted page, for the exploit to trigger.
- Attack complexityDetail
Attack complexity is high because the attacker must first have compromised the renderer process before this integer overflow can be leveraged, introducing a prerequisite step beyond the attacker's direct control.
Blast Radius
- The attacker executes arbitrary code inside the Chrome sandbox, gaining full control of the sandboxed renderer process.
- Confidential data processed within the renderer, including page content and in-memory credentials, is readable by the attacker.
- The attacker can modify data handled by the renderer process, enabling tampering with rendered content or in-process state.
- If combined with a sandbox-escape primitive, the attacker moves from the sandboxed renderer to the underlying host process.
How HarborGuard Handles This
Available on HarborGuard: any image carrying Google Chrome below 148.0.7778.216 is matched against this CVE within minutes of the advisory entering upstream feeds, with no manual scan trigger required. A rebuilt image at the fix version (148.0.7778.216) is available for affected environments; for customers who opt into auto-remediation, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes, covering the rebuild, regression run, and PR opened against affected workloads. Customers whose compliance policy does not permit auto-remediation receive a prioritized finding routed to their configured inbox so they can drive the upgrade manually. Because this exploit requires a pre-compromised renderer, network-policy controls that restrict outbound connections from container workloads running Chrome provide a useful compensating control while an upgrade is staged.
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H