CVE-2026-103631: Buffer overflow in WebRTC
Buffer overflow in WebRTC in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 154.0.8037.97
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which Chrome versions need to be updated?
Google Chrome versions prior to 154.0.8037.97 are affected. Update Chrome to 154.0.8037.97 or a later version.
What does an attacker need to exploit this issue?
An attacker needs to induce a user to load a crafted HTML page remotely. Successful exploitation can execute arbitrary code inside the Chrome sandbox.
Are users exposed through normal web browsing?
Yes. The issue is reachable through a crafted HTML page, so users running an affected Chrome version may be exposed when visiting attacker-controlled web content.