Executive brief
A vulnerability exists in Google Chrome's WebRTC component, which is used for real-time communication like video and audio calls in the browser. By tricking a user into visiting a specially crafted website, a remote attacker could potentially read sensitive information from the browser's memory. While this could lead to data exposure, the security impact is currently rated as low by the developer.
Technical details
A heap-based buffer overflow (CWE-122) exists in the WebRTC implementation within Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform an out-of-bounds memory read. This could potentially lead to the disclosure of sensitive information from the heap. The issue was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. The Chromium team has classified this vulnerability with a 'Low' security severity.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date