CVE-2026-9962
8.8Google · Chrome
A use-after-free vulnerability in the WebRTC component of Google Chrome allows remote attackers to trigger memory corruption and potentially execute arbitrary code.
Executive summary
Google Chrome versions prior to 148 are vulnerable to a use-after-free defect in WebRTC that could lead to remote code execution.
Vulnerability
This is a use-after-free vulnerability occurring in the WebRTC implementation. The vulnerability is triggered via user interaction (UI:R), meaning an attacker must entice a user to visit a malicious site or interact with specially crafted web content.
Business impact
Successful exploitation allows an attacker to execute arbitrary code within the context of the browser. Given the CVSS score of 8.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, or the installation of malware on the host machine.
Remediation
Immediate Action: Update all Google Chrome instances to version 148.0.7778.216 or later immediately.
Proactive Monitoring: Monitor browser-based traffic and endpoint logs for unusual processes spawned by the Chrome browser executable.
Compensating Controls: Ensure that enterprise endpoint protection (EDR) solutions are active to detect and block malicious payloads typically associated with browser-based memory corruption attacks.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high CVSS score reflects the potential for severe impact if this vulnerability is weaponized. Administrators should prioritize deploying the latest stable channel update for Google Chrome across the entire fleet to mitigate the risk of remote code execution.