Executive brief
Google Chrome's WebRTC component contains a buffer overflow vulnerability that could allow an attacker to execute arbitrary code within the browser's sandboxed process by opening a crafted HTML page. This could lead to unauthorized code execution and compromise of the browser sandbox, potentially enabling access to sensitive user data or further system compromise.
Technical details
A buffer overflow vulnerability exists in the WebRTC component of Google Chrome versions prior to 152.0.7977.65. The vulnerability can be exploited via a specially crafted HTML page without requiring authentication or user interaction beyond opening the malicious page. Upon successful exploitation, an attacker can execute arbitrary code within the Chrome sandbox. The vulnerability was patched in Chrome 152.0.7977.65 and later versions. While the Chromium project classified this as "Medium" severity, external analysis assigned it a CVSS score of 8.8 (High).
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 and later