Junglewise Threat Intelligence

CVE-2026-9988: Google Chrome use after free in WebRTC

CVE-2026-9988 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's WebRTC component, which handles real-time communication like video and audio calls. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to break out of the browser's security sandbox. This could lead to unauthorized access to the underlying operating system and sensitive user data.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in the WebRTC component of Google Chrome for Linux. The flaw is triggered when the browser incorrectly manages memory during the processing of WebRTC content, which can be reached by a remote attacker through a malicious HTML page. Successful exploitation could allow an attacker to bypass the Chromium sandbox, potentially leading to arbitrary code execution on the host system. The issue is resolved in Google Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats