Google Chrome contains an integer overflow condition in the PDF viewer related to bad arguments passed to a sampled function. With a specially crafted PDF file, a context-dependent attacker can cause an out-of-bounds read that may lead to a crash or potentially allow disclosure of memory contents.
Classification
Location:
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
PoC Public
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Web Related
Solution
Upgrade to version 19.0.1084.46 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.