Description
Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution inside Chrome sandbox
Action: Immediate Patch
AI Analysis

Impact

Google Chrome versions prior to 152.0.7977.65 contain a use‑after‑free flaw in the WebRTC implementation that allows a malicious web page to trigger arbitrary code execution within the browser sandbox. This flaw is classified as a high‑severity vulnerability and can be leveraged by an attacker to compromise the host system if the victim visits a crafted web page.

Affected Systems

The issue affects Google Chrome across all platforms that include the WebRTC engine. Any instance of Chrome running a version earlier than 152.0.7977.65 is susceptible; newer releases patch the vulnerability.

Risk and Exploitability

The attack vector requires a victim to open a malicious web page, thus exploitation is likely in scenarios where users browse untrusted content. Although no EPSS or KEV data is currently available, the absence of such metrics does not diminish the high impact inherent to this flaw. The CVSS score is 8.8, indicating a high severity, and organizations should treat this as a top‑priority risk.

Generated by OpenCVE AI on August 26, 2026 at 02:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or later, ensuring the latest security patches are installed.
  • If an update cannot be performed immediately, disable WebRTC usage via browser settings or a security extension until the patch is applied.
  • Apply organizational update policies that enforce automatic or timely updates of Chrome to prevent exploitation.

Generated by OpenCVE AI on August 26, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use After Free in WebRTC Enables Remote Code Execution in Chrome

Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:56:01.081Z

Reserved: 2026-08-25T06:11:06.883Z

Link: CVE-2026-79187

cve-icon Vulnrichment

Updated: 2026-08-26T00:07:23.378Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:12.380

Modified: 2026-08-27T13:14:38.630

Link: CVE-2026-79187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T05:15:04Z

Weaknesses