
CVE-2026-5287 Use after free in PDF in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium se… https://www.cve.org/CVERecord?id=CVE-2026-5287
Post summary
The post reports a newly disclosed use‑after‑free vulnerability in Chrome's PDF engine that allows arbitrary code execution from a crafted PDF, with no patch or known exploitation mentioned.

