Junglewise Threat Intelligence

CVE-2026-17884: Google Chrome object lifecycle issue in WebRTC

CVE-2026-17884 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contains a vulnerability in its WebRTC component, which handles real-time communication like video and audio calls. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, this could lead to memory corruption, potentially causing the browser to crash or allowing the attacker to disrupt the user's session.

Technical details

An object lifecycle vulnerability exists in the WebRTC component of Google Chrome. The flaw is rooted in improper management of object lifetimes, which can be triggered when the browser processes a maliciously crafted HTML page. A remote, unauthenticated attacker can leverage this to cause heap corruption. While the specific mechanism (e.g., use-after-free or double-free) is not explicitly detailed in the advisory beyond 'object lifecycle issue,' the impact is categorized as heap corruption. The vulnerability is addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats