Executive brief
Google Chrome's WebRTC component contains an integer overflow vulnerability that could allow an attacker to execute arbitrary code within the browser's sandbox. Users visiting a malicious web page could face potential code execution, even though Chrome's sandboxing limits the impact compared to a full system compromise.
Technical details
An integer overflow exists in Chrome's WebRTC implementation (prior to version 152.0.7977.65) that could lead to arbitrary code execution within the sandbox. The vulnerability is triggered via a crafted HTML page delivered over the network; no authentication or user interaction beyond visiting the page is required. An attacker can exploit this to execute code within the restricted sandbox environment, though breakout is not indicated. The issue was patched in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65