Executive brief
A critical security vulnerability exists in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take control of the user's computer or execute unauthorized commands. This poses a significant risk to data privacy and system integrity for users on Linux systems.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the WebRTC component of Google Chrome on Linux. The flaw occurs when the browser continues to use a memory pointer after it has been freed, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation can lead to arbitrary code execution (ACE) within the context of the browser process. Google has addressed this issue in version 148.0.7778.179 for Linux.
Affected products
- Google Chrome Prior to 148.0.7778.179 on Linux
Timeline
- 2026-04-20: other: Reported by Google internal researchers
- 2026-05-19: patched: Stable channel update released
- 2026-05-20: advisory: NVD publication date