Executive brief
A race condition vulnerability exists in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. By tricking a user into visiting a specially crafted website, a remote attacker could bypass security boundaries to access sensitive data from other open websites. This could lead to the unauthorized exposure of personal information or login sessions.
Technical details
A race condition (CWE-362) exists in the WebRTC implementation of Google Chrome for Windows. The vulnerability is triggered when the browser improperly synchronizes concurrent execution using shared resources during WebRTC operations. A remote attacker can exploit this by hosting a malicious HTML page that, when visited by a victim, triggers the race condition to bypass Same-Origin Policy (SOP) protections. This allows the attacker to leak sensitive data from different origins (cross-origin data). The issue is resolved in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
- 2026-05-28: disclosed: CVE-2026-9959 published