Junglewise Threat Intelligence

CVE-2026-9962: Google Chrome use after free in WebRTC

CVE-2026-9962 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. By tricking a user into visiting a specially crafted website, an attacker could potentially execute unauthorized code on the user's computer. While the attack is limited by the browser's security sandbox, it could lead to service instability or be combined with other flaws to compromise user data.

Technical details

A use-after-free (UAF) vulnerability exists in the WebRTC implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for objects during real-time communication sessions. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code in the context of the browser's sandboxed process. The issue is resolved in Google Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats