Description
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow bug in the WebRTC subsystem of Google Chrome allows a malicious web page to trigger an out‑of‑bounds write, leading to arbitrary code execution within the sandboxed context of the browser. The weakness is classified as CWE-787, an Out‑of‑Bounds Write. The impact is that a remote attacker can execute code with the privileges of the Chrome process, potentially gaining control over the user’s system or data that the browser can access.

Affected Systems

Google Chrome versions prior to 148.0.7778.96 are affected. The vulnerability is present in all platforms supported by Chrome that include the WebRTC component.

Risk and Exploitability

The exploit requires the victim to visit a crafted web page that takes advantage of the WebRTC stack; the attack vector is therefore remote via the network. The CVSS score of 8.8 indicates a High severity impact, while Chromium labels this vulnerability as Medium severity, suggesting that while exploitation is possible it may not grant full system compromise. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The lack of an EPSS score and KEV designation indicates a moderate probability of exploitation, but the threat remains significant due to the potential for arbitrary code execution.

Generated by OpenCVE AI on May 7, 2026 at 01:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 148.0.7778.96 or newer.
  • Enable automatic updates or regularly check for Chrome security releases.
  • Restrict or block access to untrusted websites that may deliver malicious WebRTC content.
  • If high risk is acceptable, consider disabling the WebRTC feature entirely via Chrome policy settings.

Generated by OpenCVE AI on May 7, 2026 at 01:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 07 May 2026 02:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in WebRTC Enabling Remote Code Execution via Crafted HTML Page

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 06 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in WebRTC Enabling Remote Code Execution via Crafted HTML Page

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-07T03:56:21.027Z

Reserved: 2026-05-05T22:59:18.358Z

Link: CVE-2026-7951

cve-icon Vulnrichment

Updated: 2026-05-06T19:37:37.804Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:43.410

Modified: 2026-05-07T02:07:07.333

Link: CVE-2026-7951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T01:45:18Z

Weaknesses