Junglewise Threat Intelligence

CVE-2026-14078: Google Chrome privilege escalation in WebRTC

CVE-2026-14078 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's WebRTC component, which is used for real-time communication like video and audio calls in the browser. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to gain higher-level permissions on the user's system. While rated as low severity, it represents a weakness in how the browser handles untrusted data from the web.

Technical details

A privilege escalation vulnerability exists in the WebRTC component of Google Chrome due to insufficient validation of untrusted input. The flaw can be triggered by a remote attacker who convinces a user to load a maliciously crafted HTML page. Successful exploitation allows the attacker to escalate privileges within the context of the browser environment. The issue is addressed in Google Chrome version 150.0.7871.47 and later. The vulnerability is classified by Chromium developers as Low severity.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats