Junglewise Threat Intelligence

CVE-2026-12461: Google Chrome out of bounds read in WebRTC

CVE-2026-12461 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebRTC component, which handles real-time communication like video and audio calls, could allow a remote attacker to access sensitive information from the browser's memory. This occurs if a user visits a specially crafted, malicious website, potentially leading to the exposure of private data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the WebRTC component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read data beyond the intended buffer in the process memory. This can lead to the disclosure of sensitive information that could be used to facilitate further attacks or bypass security mitigations like ASLR. The vulnerability was addressed in Chrome version 149.0.7827.155. Exploitation requires user interaction (visiting a malicious site) but no special privileges.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-29: other: Reported to Google
  • 2026-06-16: patched: Fixed in stable channel update 149.0.7827.155/.156
  • 2026-06-17: disclosed: NVD publication date

References

Related threats