CVE-2026-79187
8.8Google · Chrome
A use after free vulnerability in the WebRTC implementation of Google Chrome could allow a remote attacker to execute arbitrary code.
Executive summary
A high severity use after free vulnerability in Google Chrome, identified as CVE-2026-79187, presents a serious risk of arbitrary code execution through the WebRTC component.
Vulnerability
This vulnerability is a use after free (CWE-416) flaw residing in the WebRTC stack of the browser. An unauthenticated attacker can exploit this by manipulating WebRTC sessions to cause a memory corruption event, which may lead to code execution.
Business impact
With a CVSS score of 8.8, this vulnerability represents a significant threat to business operations. Exploitation could allow an attacker to execute arbitrary code with the privileges of the browser process, leading to unauthorized access to sensitive user data and potential compromise of the local host system.
Remediation
Immediate Action: Apply the latest security updates provided by Google to update Chrome to version 152.0.7977.65 or higher.
Proactive Monitoring: Review security logs for indicators of compromised WebRTC traffic or unusual browser process activity.
Compensating Controls: Utilize endpoint protection platforms that can detect and block malicious memory manipulation attempts at the process level.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability necessitates immediate attention from IT administrators. To maintain a secure posture, ensure that all instances of Google Chrome are updated to the patched version as soon as possible, as this remains the primary defense against this class of exploit.