Junglewise Threat Intelligence

CVE-2026-9959: Google Chrome race condition in WebRTC

CVE-2026-9959 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A race condition vulnerability exists in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. By tricking a user into visiting a specially crafted website, a remote attacker could bypass security boundaries to access sensitive data from other open websites. This could lead to the unauthorized exposure of personal information or login sessions.

Technical details

A race condition (CWE-362) exists in the WebRTC implementation of Google Chrome for Windows. The vulnerability is triggered when the browser improperly synchronizes concurrent execution using shared resources during WebRTC operations. A remote attacker can exploit this by hosting a malicious HTML page that, when visited by a victim, triggers the race condition to bypass Same-Origin Policy (SOP) protections. This allows the attacker to leak sensitive data from different origins (cross-origin data). The issue is resolved in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
  • 2026-05-28: disclosed: CVE-2026-9959 published

References

Related threats