Junglewise Threat Intelligence

CVE-2026-8526: Google Chrome out of bounds write in WebRTC

CVE-2026-8526 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls, could allow an attacker to execute malicious code. By tricking a user into visiting a specially crafted website, an attacker could gain unauthorized access within the browser's security sandbox. This could lead to the compromise of browser data or be used as a stepping stone for further attacks on the user's system.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the WebRTC implementation of Google Chrome prior to version 148.0.7778.168. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to perform memory corruption. Successful exploitation enables arbitrary code execution within the confines of the Chromium sandbox. While the sandbox limits direct access to the underlying operating system, this vulnerability provides a critical foothold for attackers to compromise browser sessions or chain with other exploits to escape the sandbox. Google has addressed this in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome Prior to 148.0.7778.168

Timeline

  • 2026-02-22: other: Vulnerability reported by researcher
  • 2026-05-12: patched: Fixed in Chrome version 148.0.7778.168
  • 2026-05-14: disclosed: CVE published to NVD

References

Related threats