Junglewise Threat Intelligence

CVE-2026-10947: Google Chrome use after free in WebRTC

CVE-2026-10947 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebRTC component, which handles real-time communication like video and voice calls, could allow an attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or be combined with other flaws to compromise the entire system.

Technical details

A use-after-free (UAF) vulnerability exists in the WebRTC component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of WebRTC-related content, such as during a video or audio stream setup. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code within the context of the Chrome renderer process sandbox. Users are advised to update to version 149.0.7827.53 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome Stable Channel Update released version 149.0.7827.53
  • 2026-06-04: disclosed: CVE published in NVD

References

Related threats