Description
Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Google Chrome versions before 154.0.8037.97 contain a buffer overflow in the WebRTC component. An attacker can supply a specially crafted HTML page that triggers the overflow, enabling them to run arbitrary code inside Chrome's sandbox. The vulnerability is a classic buffer overflow (CWE‑122) and, if successfully exploited, could lead to full system compromise with the privileges granted to the user’s sandbox.

Affected Systems

All users of Google Chrome on any platform who are running Chrome prior to version 154.0.8037.97 are affected. The issue was identified in the WebRTC module and applies to the stable channel of Chrome. Users of newer releases are not impacted.

Risk and Exploitability

The flaw is a remote, cross‑site vulnerability that requires nothing more than the user loading a malicious web page. The severity is rated high, but no exploit probability (EPSS) data is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the vulnerability can be triggered via standard browser activity, the likelihood of exploitation is non‑negligible, especially in environments lacking robust web filtering.

Generated by OpenCVE AI on October 2, 2026 at 17:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 154.0.8037.97 or later.
  • Use enterprise policy to disable or restrict WebRTC if updates cannot be applied immediately.
  • Implement web filtering or sandboxing solutions to block known malicious domains that could host crafted HTML.

Generated by OpenCVE AI on October 2, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via WebRTC Buffer Overflow in Chrome

Fri, 02 Oct 2026 16:15:00 +0000

Type Values Removed Values Added
Description Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-122
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-02T16:07:56.360Z

Reserved: 2026-09-30T23:12:27.846Z

Link: CVE-2026-103631

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T16:16:44.260

Modified: 2026-10-02T17:47:56.067

Link: CVE-2026-103631

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T17:30:18Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow