Junglewise Threat Intelligence

CVE-2026-87430: Google Chrome buffer overflow in WebRTC

CVE-2026-87430 · Severity: high · CVSS 8.8 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebRTC component contains a buffer overflow vulnerability that could allow an attacker to execute malicious code within the browser's security sandbox by delivering a crafted web page. This could lead to compromise of user data processed within the browser or serve as a stepping stone for further system exploitation.

Technical details

The vulnerability is a buffer overflow in the WebRTC component of Google Chrome versions prior to 153.0.8010.36. An unauthenticated remote attacker can trigger the overflow by hosting or distributing a specially crafted HTML page that exploits the vulnerability. While execution occurs within the browser's sandbox (limiting direct system impact), successful exploitation could allow arbitrary code execution within that sandboxed environment. The vulnerability has been patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats