Junglewise Threat Intelligence

CVE-2026-87579: Google Chrome buffer overflow in WebRTC

CVE-2026-87579 · Severity: high · CVSS 8.8 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a buffer overflow vulnerability in its WebRTC component that allows remote attackers to execute arbitrary code within the browser's sandbox. An attacker can trigger this vulnerability by crafting a malicious HTML page, potentially compromising user data or browser integrity. Users running Chrome prior to version 153.0.8010.36 are at risk.

Technical details

A buffer overflow vulnerability exists in the WebRTC implementation of Google Chrome prior to version 153.0.8010.36. The vulnerability is triggered via a crafted HTML page that interacts with WebRTC functionality, allowing a remote attacker to write beyond buffer boundaries. While execution occurs within the browser sandbox (limiting full system compromise), a successful exploit can lead to arbitrary code execution within the sandboxed process. The vulnerability was fixed in Chrome 153.0.8010.36 and later versions. No active in-the-wild exploitation has been reported.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats