CVE-2026-17884
Google · Chrome
An object lifecycle vulnerability exists in the WebRTC component of Google Chrome prior to version 151, which may allow for memory corruption and arbitrary code execution.
Executive summary
An object lifecycle vulnerability in the Google Chrome WebRTC component poses a significant risk of arbitrary code execution for affected users.
Vulnerability
This is an object lifecycle flaw within the WebRTC implementation. It is triggered via network interaction and requires user interaction, such as visiting a malicious webpage, to execute successfully.
Business impact
The exploitation of this vulnerability could lead to a total compromise of the affected system, including unauthorized data access and potential lateral movement within the network. With a CVSS score of 8.8, this high severity issue represents a significant threat to organizational security and data integrity.
Remediation
Immediate Action: Update Google Chrome to version 151.0.7922.72 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Review browser logs and endpoint security telemetry for unusual process behavior or unexpected crashes related to WebRTC activity.
Compensating Controls: Deploy endpoint protection solutions that can detect and block memory corruption attempts, and ensure users are trained to avoid suspicious web links.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for total system impact, organizations should prioritize the deployment of the latest Chrome security updates. Ensure that all browser instances are updated across the enterprise to mitigate the risk of exploitation.