Executive brief
A vulnerability in Google Chrome's WebRTC component could allow a malicious website to access data from other websites or browser tabs. WebRTC is the technology used for real-time communication like video calls and voice chat within the browser. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information.
Technical details
An inappropriate implementation vulnerability exists in the WebRTC component of Google Chrome. The flaw allows for a cross-origin data leak when a user visits a malicious HTML page. By exploiting this, a remote attacker can bypass Same-Origin Policy (SOP) protections to access information from different origins. The vulnerability is triggered via a network-based attack vector requiring user interaction (visiting a site). Google has addressed this issue in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome stable channel update released.
- 2026-06-04: disclosed: CVE published.