Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebRTC component, which handles real-time communication like video and audio calls, could allow a malicious website to corrupt the browser's memory. If exploited, this could lead to the browser crashing or potentially allow an attacker to gain unauthorized access to data or execute code on the user's system.
Technical details
An integer overflow vulnerability exists in the WebRTC component of Google Chrome prior to version 147.0.7727.55. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an out-of-bounds (OOB) memory write. This is a remote attack vector that requires minimal user interaction (visiting a malicious site). While Chromium developers classified the internal severity as Low, external analysis (CISA-ADP) assigned a CVSS 3.1 score of 8.8, indicating a high potential for impact on confidentiality, integrity, and availability. The issue is resolved in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-22: other: Vulnerability reported to Chrome by researcher c6eed09fc8b174b0f3eebedcceb1e792
- 2026-04-07: patched: Chrome version 147.0.7727.55 released to stable channel
- 2026-04-08: disclosed: Public advisory published