Junglewise Threat Intelligence

CVE-2026-79027: Google Chrome use-after-free in WebRTC

CVE-2026-79027 · Severity: high · CVSS 8.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users to access web content and services. A use-after-free vulnerability in Chrome's WebRTC component (which enables real-time voice and video communication) could allow attackers to execute malicious code within the browser's sandboxed environment by sending specially crafted network traffic, potentially compromising user data or enabling malware installation.

Technical details

A use-after-free vulnerability exists in the WebRTC component of Google Chrome prior to version 152.0.7977.65. The vulnerability is triggered via crafted network traffic and requires no user authentication. An attacker on the network can trigger memory-safety corruption by forcing the reuse of freed memory, achieving arbitrary code execution within the browser's sandbox. Although the sandbox provides a secondary containment layer, exploitation allows attackers to escape user-process isolation and potentially access local system resources. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Patch released in Chrome 152.0.7977.65
  • 2026-08-25: advisory

References

Related threats