Junglewise Threat Intelligence

CVE-2026-10943: Google Chrome use after free in WebRTC

CVE-2026-10943 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized data access or be used as a stepping stone for further system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the WebRTC component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of WebRTC sessions, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the browser's sandboxed process. This vulnerability was reported by researcher Rayyan Kadar and is addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-20: other: Vulnerability reported by Rayyan Kadar
  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
  • 2026-06-04: disclosed: Public CVE disclosure

References

Related threats