Executive brief
A security vulnerability exists in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the browser's security 'sandbox' provides some protection, this flaw could lead to data theft or further system compromise if combined with other vulnerabilities.
Technical details
A heap-based buffer overflow (CWE-122) exists in the WebRTC implementation within Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to overflow memory buffers. This can lead to arbitrary code execution within the context of the browser's sandboxed process. The attack requires minimal user interaction (visiting a malicious URL) and has a high impact on confidentiality, integrity, and availability. The issue is resolved in Google Chrome version 148.0.7778.179 and later.
Affected products
- Google Chrome Prior to 148.0.7778.179
Timeline
- 2026-04-17: disclosed: Reported to Google by internal researchers
- 2026-05-19: patched: Stable channel update released for Windows, Mac, and Linux
- 2026-05-20: advisory: NVD publication date