CVE-2026-17884

Google · Chrome

An object lifecycle vulnerability exists in the WebRTC component of Google Chrome prior to version 151, which may allow for memory corruption and arbitrary code execution.

Executive summary

An object lifecycle vulnerability in the Google Chrome WebRTC component poses a significant risk of arbitrary code execution for affected users.

Vulnerability

This is an object lifecycle flaw within the WebRTC implementation. It is triggered via network interaction and requires user interaction, such as visiting a malicious webpage, to execute successfully.

Business impact

The exploitation of this vulnerability could lead to a total compromise of the affected system, including unauthorized data access and potential lateral movement within the network. With a CVSS score of 8.8, this high severity issue represents a significant threat to organizational security and data integrity.

Remediation

Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.

Proactive Monitoring: Review browser logs and endpoint security telemetry for unusual process behavior or unexpected crashes related to WebRTC activity.

Compensating Controls: Deploy endpoint protection solutions that can detect and block memory corruption attempts, and ensure users are trained to avoid suspicious web links.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the potential for total system impact, organizations should prioritize the deployment of the latest Chrome security updates. Ensure that all browser instances are updated across the enterprise to mitigate the risk of exploitation.