Heap buffer overflow in PDFium in Google Chrome on Windows prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
https://issues.chromium.org/issues/500036290
https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html