Executive brief
Google Chrome's WebRTC component contains a buffer overflow vulnerability that could allow an attacker to execute malicious code within the browser's security sandbox by delivering a crafted web page. This could lead to compromise of user data processed within the browser or serve as a stepping stone for further system exploitation.
Technical details
The vulnerability is a buffer overflow in the WebRTC component of Google Chrome versions prior to 153.0.8010.36. An unauthenticated remote attacker can trigger the overflow by hosting or distributing a specially crafted HTML page that exploits the vulnerability. While execution occurs within the browser's sandbox (limiting direct system impact), successful exploitation could allow arbitrary code execution within that sandboxed environment. The vulnerability has been patched in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched