EIP-2026-103622

PRE-CVE

pdfium - opj_j2k_read_mcc 'libopenjpeg' Heap Out-of-Bounds Read

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103622. PoCs published by Google Security Research.

AI-analyzed exploit summary This is a crash report from a heap-buffer-overflow vulnerability in PDFium's OpenJPEG library (j2k.c) during PDF fuzzing. The report includes an AddressSanitizer trace but no exploit code.

Description

pdfium - opj_j2k_read_mcc 'libopenjpeg' Heap Out-of-Bounds Read

Exploits (1)

exploitdb WRITEUP VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/39322

This is a crash report from a heap-buffer-overflow vulnerability in PDFium's OpenJPEG library (j2k.c) during PDF fuzzing. The report includes an AddressSanitizer trace but no exploit code.

Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: PDFium (Chrome PDF renderer) with OpenJPEG 2.0
No auth needed
Prerequisites: Malformed PDF file with crafted J2K image
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026