CVE-2026-7987

8.8

Google · Chrome

A use-after-free vulnerability in WebRTC in Google Chrome prior to version 148.0.7778.96 allows remote code execution via a crafted HTML page.

Executive summary

Google Chrome contains a use-after-free vulnerability in WebRTC that allows a remote attacker to execute arbitrary code via a crafted HTML page.

Vulnerability

This is a use-after-free memory corruption flaw (CWE-416) within the WebRTC component, triggered when an unauthenticated attacker entices a user to visit a malicious HTML page requiring user interaction.

Business impact

Successful exploitation of this flaw can lead to total system compromise, allowing an attacker to execute arbitrary code within the browser sandbox context. This poses severe risks to confidentiality, integrity, and availability of user data and host systems. The high CVSS score of 8.8 reflects the severity of potential remote code execution despite the requirement for user interaction.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.96 or later by applying the official vendor security release immediately.

Proactive Monitoring: Monitor client endpoints for unexpected browser crashes, anomalous child process behavior, or unauthorized network connections originating from browser instances.

Compensating Controls: Ensure browser security features, such as strict site isolation and up-to-date endpoint protection agents, are enforced across all managed workstations.

Exploitation status

Public Exploit Available: No (false / unknown)

Analyst recommendation

Given the high severity rating and the potential for remote code execution, IT administrators must prioritize updating Google Chrome across all endpoints without delay. Deploying the latest browser versions is critical to neutralizing the underlying memory corruption risk.

More Google CVEs

Sources