Junglewise Threat Intelligence

CVE-2026-15121: Google Chrome use after free in WebRTC

CVE-2026-15121 · Severity: info · CVSS 8.8 · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's WebRTC component, which is used for real-time communication like video calls and voice chat. By tricking a user into visiting a specially crafted website, an attacker could potentially execute unauthorized code on the user's computer. While the attack is limited by the browser's security sandbox, it could still lead to significant security compromises or service instability.

Technical details

A use-after-free vulnerability exists in the WebRTC component of Google Chrome prior to version 150.0.7871.115. The flaw is triggered when the browser incorrectly manages memory during the processing of WebRTC content, which can be exploited by a remote attacker using a crafted HTML page. Successful exploitation allows for arbitrary code execution within the context of the browser's sandbox. The vulnerability was reported by Google internal researchers and is addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome < 150.0.7871.115

Timeline

  • 2026-06-14: disclosed: Reported to the Chromium project
  • 2026-07-08: patched: Fixed in version 150.0.7871.115
  • 2026-07-08: advisory: NVD and Chrome Release blog published

References

Related threats