CVE-2026-17951

Google · Chrome

A heap buffer overflow vulnerability exists in the WebRTC component of Google Chrome, potentially facilitating arbitrary code execution.

Executive summary

A high-severity heap buffer overflow in Google Chrome's WebRTC implementation exposes users to significant risk of remote code execution.

Vulnerability

This vulnerability is a heap buffer overflow flaw located within the WebRTC component of Google Chrome. An unauthenticated remote attacker can exploit this via malicious web content, requiring user interaction to trigger the overflow and execute arbitrary code.

Business impact

Exploitation of this vulnerability allows for unauthorized code execution within the browser's sandbox, which can lead to data theft, malware installation, or full system takeover. The 8.8 CVSS score reflects the high impact of this vulnerability, making it a critical security concern for any organization relying on Chrome for daily operations.

Remediation

Immediate Action: Deploy the security update to version 151.0.7922.72 or later across all devices running Google Chrome.

Proactive Monitoring: Monitor browser logs and system performance metrics for anomalies, particularly those related to real-time communication modules or media stream processing.

Compensating Controls: Deploy web filtering and security proxies to block access to known malicious domains that might host exploit payloads targeting browser vulnerabilities.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant threat to endpoint security. IT teams should ensure that all instances of Google Chrome are updated to the patched version as soon as possible to mitigate the risk of exploitation.