Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebRTC component, which handles real-time communication like video and audio calls, could allow an attacker to cause memory corruption. In a real-world scenario, an attacker who has already gained a foothold in the browser's graphics processing (GPU) system could use a specially crafted webpage to further compromise the browser, potentially leading to unauthorized access or instability.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the WebRTC component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the GPU process. Successful exploitation can lead to heap corruption, potentially allowing for further sandbox escape or arbitrary code execution within the context of the browser. The vulnerability was addressed in Chrome version 149.0.7827.103 for Windows and Mac, and 149.0.7827.102 for Linux.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-19: disclosed: Reported by Google researchers
- 2026-06-08: patched: Stable channel update released
- 2026-06-09: advisory: NVD publication date