CVE-2026-7951

8.8

Google · Chrome

An out of bounds write vulnerability in WebRTC within Google Chrome prior to 148.0.7778.96 allows remote code execution.

Executive summary

An out of bounds write vulnerability in WebRTC within Google Chrome prior to version 148.0.7778.96 allows a remote attacker to achieve arbitrary code execution via a crafted HTML page.

Vulnerability

This is an out of bounds write flaw (CWE-787) in the WebRTC component that requires user interaction, specifically visiting a crafted webpage, with an unauthenticated attacker model.

Business impact

A successful exploit of this vulnerability can lead to total system compromise, potentially allowing attackers to execute arbitrary code within the browser sandbox context, leading to unauthorized data access or complete system disruption. Although the CVSS score is 8.8, indicating high severity, the requirement for user interaction slightly reduces the automatability of the threat while retaining severe technical impact.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later immediately.

Proactive Monitoring: Monitor client endpoints for abnormal browser crashes, unexpected process spawns originating from the browser, or unauthorized network connections.

Compensating Controls: Ensure endpoint detection and response agents are active on all workstations to detect anomalous behavior resulting from browser exploitation.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high severity score and the potential for arbitrary code execution, administrators must prioritize updating all instances of Google Chrome across the enterprise immediately. Timely patching is critical to mitigate the risk of browser-based attacks.

More Google CVEs

Sources