CVE-2026-2648Disclosure(google / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chromium security severity: High)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-02-19); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-02-18: 1Mentions · 2026-02-19: 4Mentions · 2026-02-20: 2Mentions · 2026-02-23: 1Mentions · 2026-02-24: 1Patch / Workaround · 2026-02-19: 2Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 2Technical Details · 2026-02-24: 102-1802-1902-2002-2302-24
Signal classification3 categories
Disclosure
555.6%
Patch
333.3%
General
111.1%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-181
Disclosure1
2026-02-194
Disclosure3Patch1
2026-02-202
Disclosure1Patch1
2026-02-231
General1
2026-02-241
Patch1
Full discourse9 posts
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-2648)[477033835]Heap-BoF(OOBR) in J2K/JPEG 2000(libopenjpeg) https://pdfium-review.googlesource.com/c/pdfium/+/142390 https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_18.html Reported by soiax

    Post summary

    The post announces a heap buffer overflow (out‑of‑bounds read) in libopenjpeg used by PDFium, accompanied by a code review link and a Chrome update that addresses the issue.

    05034162.5K
    4.8K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Google Pushes Emergency Chrome Patch for High-Severity PDFium & V8 Flaws (CVE-2026-2648/2649) Google released an emergency Chrome Stable update (145.0.7632.109/110 for Windows/macOS; 144.0.7559.109 for Linux) fixing two high-severity memory issues—PDFium heap buffer overflow (CVE-2026-2648) and a V8 integer overflow (CVE-2026-2649)—plus a Media heap overflow (CVE-2026-2650). This matters because these core-engine bugs can enable crashes or arbitrary code execution via malicious content, so rapid patching reduces browser RCE risk across enterprises. 🎯 Target: Global #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/google-chrome-emergency-security-update/

    Post summary

    Google issued an emergency patch for high‑severity PDFium and V8 memory issues (CVE‑2026‑2648/2649) to mitigate potential RCE risks.

    00001108
    196 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🔥 Google Chrome emergency: CVE-2026-2648 PDFium heap overflow patched 145.0.7632.109. V8 high too. Update ASAP! Thread 👇 https://thecyberedition.com/chrome-cve-2026-2648/ #ZeroDaysAndCVEs #Chrome #Cybersecurity

    Post summary

    Google Chrome issued an emergency patch (v145.0.7632.109) for CVE-2026-2648, a PDFium heap‑overflow vulnerability also affecting V8, urging users to update immediately.

    0000156
    668 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Google releases an urgent Chrome update to patch high-severity flaws in PDFium (CVE-2026-2648) and the V8 engine (CVE-2026-2649). Update to 145 now. #ChromeUpdate #CyberSecurity #InfoSec #CVE20262648 #V8Engine #PatchNow https://securityonline.info/urgent-chrome-patch-google-fixes-high-severity-pdf-and-v8-engine-flaws/

    Post summary

    Google has released an urgent Chrome update (v145) to address high‑severity CVE‑2026‑2648 and CVE‑2026‑2649 affecting PDFium and V8, urging users to update.

    00001186
    10.3K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Google Chrome (CVE-2026-2648) https://vuldb.com/?id.346667

    Post summary

    A new vulnerability (CVE-2026-2648) has been disclosed for Google Chrome with increased severity, but no technical details, patches, or exploitation information are provided.

    0001062
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2648 Heap Buffer Overflow in PDFium Enables Remote Memory Write... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2648 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces a heap buffer overflow vulnerability in PDFium (CVE-2026-2648) that allows remote memory writes, and provides links to detailed information.

    0001079
    4.0K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Google ❗ CVE-2026-2649 ❗ CVE-2026-2648 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-google-2/ https://t.co/PEnhwK5AvC

    Post summary

    The tweet lists two CVEs affecting Google products and links to external sources for more information, but offers no further details.

    00000121
    6.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    CVE-2026-2648: `Chromium` `PDFium` heap buffer overflow. Crafted PDFs can lead to out-of-bounds memory writes. Monitor for vendor updates. #chromium #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-2648-chromium-pdfium-heap-overflow

    Post summary

    Chromium’s PDFium component has a heap buffer overflow (CVE‑2026‑2648) that allows crafted PDFs to cause out‑of‑bounds memory writes. No PoC, exploit code, or patch details are provided in the text.

    0000031
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2648 Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chro… https://www.cve.org/CVERecord?id=CVE-2026-2648

    Post summary

    The text details a heap buffer overflow in PDFium that allows a remote attacker to perform an out‑of‑bounds memory write via a crafted PDF file, with no mention of exploitation or mitigations.

    00000133
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more