Description
Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap buffer overflow exists in the WebRTC component of Google Chrome running on Windows. An attacker can exploit the flaw by delivering a specially crafted HTML page, which causes Chrome to read or write memory outside its intended bounds and execute arbitrary code. The vulnerability is categorized as high severity within Chromium's own security rating, reflecting the potential to compromise confidentiality, integrity, and availability of the affected system.

Affected Systems

The issue affects Google Chrome browsers on Windows platforms with version numbers earlier than 149.0.7827.155. Any installation of Chrome on Windows that has not yet applied the latest update remains vulnerable. The CNA vendor product "Google:Chrome" is the sole affected product.

Risk and Exploitability

The EPSS score is reported as less than 1%, indicating an extremely low probability of public exploitation at the time of this analysis. The vulnerability is not listed in CISA's KEV catalog. Despite the low probability, the nature of the flaw—remote code execution via a crafted HTML page—makes it highly dangerous if leveraged. Attackers would likely target users on networks where they can supply malicious web content, such as compromised websites or drive‑by download scenarios. No current exploits are publicly available, but the high severity and remote exploitability warrant immediate attention.

Generated by OpenCVE AI on June 17, 2026 at 18:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Chrome update that includes version 149.0.7827.155 or later, which patches the WebRTC heap overflow.
  • Ensure that Chrome’s automatic update feature is enabled and that users regularly check for new releases to stay protected against future vulnerabilities.
  • If a timely update is not possible, consider switching to an alternative browser that does not have this specific vulnerability.

Generated by OpenCVE AI on June 17, 2026 at 18:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-17T13:20:12.256Z

Reserved: 2026-06-16T19:38:33.475Z

Link: CVE-2026-12466

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T07:15:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow