CVE-2026-5889 is a cryptographic flaw in PDFium, Google Chrome's PDF rendering engine, affecting versions prior to 147.0.7727.55. The vulnerability allows attackers to extract potentially sensitive information from encrypted PDFs through brute-force attacks, representing a medium-severity threat to confidentiality. The attack requires network access and user interaction (opening a malicious PDF), but has low technical complexity and no special privileges. The CVSS score of 4.3 reflects limited impact, confined to confidentiality breaches with no effect on integrity or availability. The EPSS score of 0.000060 indicates this vulnerability is uncommon relative to the broader CVE landscape. Exploitation status indicates minimal current risk: the vulnerability is not tracked on CISA's Known Exploited Vulnerabilities list, lacks public exploit code, and remains inactive on security watch lists. This suggests limited real-world exploitation activity, though organizations should still patch to Chrome 147.0.7727.55 or later to address the underlying cryptographic weakness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.