Junglewise Threat Intelligence

CVE-2026-87630: Google Chrome integer overflow in WebRTC

CVE-2026-87630 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebRTC component contains an integer overflow vulnerability that allows a remote attacker to read memory contents within the browser's sandbox by opening a specially crafted HTML page. This could expose sensitive data processed by web applications, though the impact is limited by the sandbox environment.

Technical details

An integer overflow vulnerability exists in the WebRTC component of Google Chrome prior to version 153.0.8010.36. The vulnerability is triggered when processing crafted HTML content, causing integer arithmetic to wrap and potentially leading to heap-based buffer overread. An attacker must trick a user into visiting a malicious web page; user interaction is required. Successful exploitation allows an attacker to read arbitrary memory within the Chrome sandbox process, potentially exposing session data, cached credentials, or other sensitive information. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36

References

Related threats