Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its WebRTC component, which handles real-time communication like video and audio calls, could allow an attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it still poses a significant risk to data privacy and system integrity.
Technical details
A use-after-free (UAF) vulnerability exists in the WebRTC component of Google Chrome prior to version 147.0.7727.138. The flaw is triggered when the browser incorrectly manages memory during real-time communication processes, allowing an attacker to reference memory after it has been freed. By tricking a user into visiting a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution within the Chromium sandbox. Users are advised to update to version 147.0.7727.138 or later to mitigate this risk.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-04-20: disclosed: Reported to Chrome by Google researchers
- 2026-04-28: advisory: NVD and Vendor advisory published
- 2026-04-28: patched: Fixed in version 147.0.7727.138