VDB
CVE-2026-2648
CVE-2026-2648
PUBLISHED
CVSS 8.800000190734863 HIGH
Heap buffer overflow in PDFium in Google Chrome prior to 145.0.7632.109 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file. (Chromium security severity: High)
EPSS 0.05% · 14.8th percentile
Risk Scores
CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.05%
14.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Edge | |
| chrome | 0 | |
| Chrome | 145.0.7632.109 |
Timeline
- Feb 18, 2026 CVE ID Reserved
- Feb 18, 2026 CVE Published
- Feb 19, 2026 EPSS Score
- Feb 19, 2026 PoC Published
- Feb 19, 2026 PoC Published
- Feb 20, 2026 PoC Published
- Feb 21, 2026 EPSS Score
- Feb 22, 2026 EPSS Score
- Feb 23, 2026 PoC Published
- Feb 24, 2026 EPSS Score
- Feb 26, 2026 EPSS Score
- Feb 26, 2026 CVE Updated
References
- https://chromereleases.googleblog.com/2026/02/stable-channel-update-for-desktop_18.html advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-2649 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-2648 advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-2650 advisory
- https://issues.chromium.org/issues/477033835 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-2648 advisory
- https://security.paloaltonetworks.com/CVE-2026-0233 advisory
- https://security.paloaltonetworks.com/CVE-2026-0234 advisory
- https://security.paloaltonetworks.com/CVE-2026-0232 advisory
- https://security.paloaltonetworks.com/PAN-SA-2026-0004 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0512 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0513 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0509 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0510 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0505 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0515 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0507 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0506 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0508 advisory
- https://advisory.splunk.com/advisories/SVD-2026-0504 advisory
…and 6 more