Executive brief
A vulnerability exists in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized access to data or be used as part of a larger attack to compromise the entire system.
Technical details
A use-after-free (UAF) vulnerability exists in the WebRTC implementation of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of WebRTC content, allowing an attacker to reference memory after it has been freed. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chromium render process sandbox. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-10975 published.