CVE-2026-7951
8.8Google · Chrome
An out of bounds write vulnerability in WebRTC within Google Chrome prior to 148.0.7778.96 allows remote code execution.
Executive summary
An out of bounds write vulnerability in WebRTC within Google Chrome prior to version 148.0.7778.96 allows a remote attacker to achieve arbitrary code execution via a crafted HTML page.
Vulnerability
This is an out of bounds write flaw (CWE-787) in the WebRTC component that requires user interaction, specifically visiting a crafted webpage, with an unauthenticated attacker model.
Business impact
A successful exploit of this vulnerability can lead to total system compromise, potentially allowing attackers to execute arbitrary code within the browser sandbox context, leading to unauthorized data access or complete system disruption. Although the CVSS score is 8.8, indicating high severity, the requirement for user interaction slightly reduces the automatability of the threat while retaining severe technical impact.
Remediation
Immediate Action: Update Google Chrome to version 148.0.7778.96 or later immediately.
Proactive Monitoring: Monitor client endpoints for abnormal browser crashes, unexpected process spawns originating from the browser, or unauthorized network connections.
Compensating Controls: Ensure endpoint detection and response agents are active on all workstations to detect anomalous behavior resulting from browser exploitation.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the high severity score and the potential for arbitrary code execution, administrators must prioritize updating all instances of Google Chrome across the enterprise immediately. Timely patching is critical to mitigate the risk of browser-based attacks.