Description
Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow exists in the WebRTC component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to trigger arbitrary code execution inside the browser’s sandbox by loading a specially crafted HTML page. The vulnerability is classified with a medium severity by Chromium’s internal review, but the potential for executing code within the sandbox is significant.

Affected Systems

Google Chrome browsers dated before 152.0.7977.65 are affected. The issue is limited to the WebRTC implementation in the stable channel releases, and does not extend to pre‑release or beta tracks beyond the specified version boundary.

Risk and Exploitability

The flaw is exploitable via standard web content delivery; a malicious page can be served over HTTP or HTTPS to a user’s browser. While the attacks are sandboxed, code execution within that sandbox can still lead to privilege escalation in certain contexts. The CVSS score of 8.8 indicates a high severity, and the EPSS score is <1%, reflecting a low but nonzero probability of exploitation. The vulnerability has not been listed in CISA’s KEV catalog. Given the high CVSS score, the risk is elevated and realistic exploitation is possible if a target user visits a malicious page.

Generated by OpenCVE AI on August 26, 2026 at 17:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Chrome update to 152.0.7977.65 or newer to remove the buffer overflow flaw.
  • If the patch cannot be applied immediately, disable the WebRTC feature through Chrome policy or the experimental flag "Enable WebRTC" to block the vulnerable component.
  • Continuously monitor Chromium security advisories and user logs for any signs of exploitation attempts on systems that remain at vulnerable versions.

Generated by OpenCVE AI on August 26, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Wed, 26 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title WebRTC Buffer Overflow Enabling Remote Code Execution in Google Chrome

Wed, 26 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title WebRTC Buffer Overflow Enabling Remote Code Execution in Google Chrome

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:57:22.589Z

Reserved: 2026-08-25T06:03:50.494Z

Link: CVE-2026-78891

cve-icon Vulnrichment

Updated: 2026-08-26T14:56:34.564Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:46.390

Modified: 2026-08-27T04:16:50.980

Link: CVE-2026-78891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T17:30:10Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow