Low chrome UAF 🔧 Commit mapped

Overview

Low
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactUse after free in PDFium
DescriptionUse after free in PDFium
ComponentPDFium
Bug ClassUAF
Tracker513689974
Fix commit09704940dd21 (pdfium) +11/-6
CISA KEVNot listed
CreditedGoogle
Disclosed2026-06-30

Changed Functions

FunctionChangeNotes
if
fxjs/xfa/cfxjse_engine.cpp
modified

Files Changed

  • fxjs/xfa/cfxjse_engine.cpp
From 09704940dd21e5a45c0d09fa917879c7e6f3bd0d Mon Sep 17 00:00:00 2001
From: Tom Sepez <tsepez@google.com>
Date: Mon, 18 May 2026 13:34:47 -0700
Subject: [PATCH] Verify document in CFXJSE_Engine::ToXFAObject()

Hardening suggestion from AI analysis.

Bug: 513689974
Change-Id: Ic04c1182781785508faf6375b0a34907a1f3baa6
Reviewed-on: https://pdfium-review.googlesource.com/c/pdfium/+/147910
Reviewed-by: Lei Zhang <thestig@chromium.org>
Commit-Queue: Tom Sepez <tsepez@chromium.org>
---

diff --git a/fxjs/xfa/cfxjse_engine.cpp b/fxjs/xfa/cfxjse_engine.cpp
index 49df538..92123aa 100644
--- a/fxjs/xfa/cfxjse_engine.cpp
+++ b/fxjs/xfa/cfxjse_engine.cpp
@@ -947,15 +947,20 @@
   if (!fxv8::IsObject(obj)) {
     return nullptr;
   }
-
-  CFXJSE_HostObject* pHostObj =
+  CFXJSE_HostObject* host_obj =
       FXJSE_RetrieveObjectBinding(obj.As<v8::Object>());
-  if (!pHostObj) {
+  if (!host_obj) {
     return nullptr;
   }
-
-  CJX_Object* pJSObject = pHostObj->AsCJXObject();
-  return pJSObject ? pJSObject->GetXFAObject() : nullptr;
+  CJX_Object* jx_obj = host_obj->AsCJXObject();
+  if (!jx_obj) {
+    return nullptr;
+  }
+  CXFA_Object* xfa_obj = jx_obj->GetXFAObject();
+  if (!xfa_obj || xfa_obj->GetDocument() != document_) {
+    return nullptr;
+  }
+  return xfa_obj;
 }
 
 v8::Local<v8::Object> CFXJSE_Engine::NewNormalXFAObject(CXFA_Object* obj) {
Loading diff…

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.