EIP-2026-103622
PRE-CVEpdfium - opj_j2k_read_mcc 'libopenjpeg' Heap Out-of-Bounds Read
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-103622. PoCs published by Google Security Research.
AI-analyzed exploit summary This is a crash report from a heap-buffer-overflow vulnerability in PDFium's OpenJPEG library (j2k.c) during PDF fuzzing. The report includes an AddressSanitizer trace but no exploit code.
Description
pdfium - opj_j2k_read_mcc 'libopenjpeg' Heap Out-of-Bounds Read
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Google Security Research · textdosmultiple
https://www.exploit-db.com/exploits/39322
This is a crash report from a heap-buffer-overflow vulnerability in PDFium's OpenJPEG library (j2k.c) during PDF fuzzing. The report includes an AddressSanitizer trace but no exploit code.
Classification
Writeup 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target:
PDFium (Chrome PDF renderer) with OpenJPEG 2.0
No auth needed
Prerequisites:
Malformed PDF file with crafted J2K image
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026