CVE-2026-79187: High Use after free in WebRTC
Chromium: CVE-2026-79187 Use after free in WebRTC
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
— NVD
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.53 - Upgrade
Upgrade
Chromium / Google Chrome (WebRTC)to a version that resolves this vulnerability.Fixed in 152.0.7977.65
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which Chrome versions need to be remediated?
Google Chrome versions prior to 152.0.7977.65 are affected. Update Chrome to 152.0.7977.65 or later.
What does an attacker need to exploit this issue?
The issue can be triggered by a remote attacker using a crafted HTML page. Successful exploitation allows arbitrary code execution inside the Chrome sandbox.
Does exploitation escape the Chrome sandbox?
The provided information states that arbitrary code execution occurs inside the sandbox. It does not establish that this vulnerability alone enables a sandbox escape.