Junglewise Threat Intelligence

CVE-2026-11667: Google Chrome out of bounds read in WebRTC

CVE-2026-11667 · Severity: info · Published 2026-06-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebRTC component, which handles real-time communication like video and audio calls, could allow an attacker to cause memory corruption. In a real-world scenario, an attacker who has already gained a foothold in the browser's graphics processing (GPU) system could use a specially crafted webpage to further compromise the browser, potentially leading to unauthorized access or instability.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the WebRTC component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the GPU process. Successful exploitation can lead to heap corruption, potentially allowing for further sandbox escape or arbitrary code execution within the context of the browser. The vulnerability was addressed in Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.103

Timeline

  • 2026-05-19: disclosed: Reported by Google researchers
  • 2026-06-08: patched: Stable channel update released
  • 2026-06-09: advisory: NVD publication date

References

Related threats