Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | PDFium Double Free Enables Remote Code Execution in Chrome Windows |
Wed, 09 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google chrome Microsoft Microsoft windows |
Wed, 09 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 09 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | PDFium Double Free Enables Remote Code Execution in Chrome Windows |
Wed, 09 Sep 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High) | |
| Weaknesses | CWE-415 | |
| References |
|
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2026-09-10T03:55:28.039Z
Reserved: 2026-09-08T22:41:29.513Z
Link: CVE-2026-87585
Updated: 2026-09-09T12:50:51.416Z
Status : Analyzed
Published: 2026-09-09T01:17:16.357
Modified: 2026-09-10T04:18:27.363
Link: CVE-2026-87585
No data.
OpenCVE Enrichment
Updated: 2026-09-09T19:30:15Z