Junglewise Threat Intelligence

CVE-2026-10948: Google Chrome use after free in WebRTC

CVE-2026-10948 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls, could allow an attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website. While the exploit is contained within the browser's security sandbox, it could lead to browser crashes or be combined with other flaws to compromise the entire system.

Technical details

A use-after-free (UAF) vulnerability exists in the WebRTC component of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of WebRTC sessions, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the browser's sandboxed process. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53/54
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats