Junglewise Threat Intelligence

CVE-2026-79187: Google Chrome use-after-free in WebRTC

CVE-2026-79187 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser that enables users to access websites and web applications. A use-after-free vulnerability in the WebRTC component allows a remote attacker to execute arbitrary code within Chrome's sandbox by tricking a user into visiting a crafted HTML page, potentially compromising user data and system security.

Technical details

CVE-2026-79187 is a use-after-free vulnerability in Google Chrome's WebRTC component. The vulnerability exists in Chrome versions prior to 152.0.7977.65 and can be triggered remotely via a crafted HTML page without requiring user authentication beyond visiting a malicious webpage. An attacker can exploit this to execute arbitrary code within the Chrome sandbox, which may allow them to escape the sandbox and compromise the underlying system. The vulnerability has been patched in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Chrome 152.0.7977.65 released with fix
  • 2026-06-12: other: Vulnerability reported to Google

References

Related threats