Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebRTC component, which handles real-time communication like video and audio calls, could allow an attacker to take control of a user's computer. This occurs if a user visits a specially crafted, malicious website, potentially leading to unauthorized data access or system compromise.
Technical details
A heap-based buffer overflow (CWE-122) exists in the WebRTC component of Google Chrome for Windows. The vulnerability is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to achieve arbitrary code execution within the context of the browser process. The attack vector is network-based and requires minimal user interaction (visiting a malicious site). This issue was addressed in Chrome version 149.0.7827.155.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-06-05: other: Reported to Google
- 2026-06-16: patched: Stable channel update released
- 2026-06-17: disclosed: CVE published