Executive brief
A security vulnerability exists in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. An attacker could use a specially crafted website to bypass security boundaries and access data from other open websites or services. This could lead to the unauthorized disclosure of sensitive user information.
Technical details
A race condition vulnerability was identified in the WebRTC component of Google Chrome for Windows. The flaw exists in versions prior to 150.0.7871.47 and can be triggered when a user visits a malicious, attacker-controlled HTML page. By exploiting this timing issue, a remote attacker can bypass Same-Origin Policy (SOP) protections to leak sensitive data across origins. The vulnerability is classified by Chromium as Medium severity and has been addressed in the stable channel update to version 150.0.7871.47 or later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory