CVE-2026-84347
massUse-after-free in Google Chrome WebRTC allows sandboxed code execution
CVE-2026-84347 is a use-after-free vulnerability (CWE-416) in the WebRTC component of Google Chrome that affects all releases prior to 152.0.7977.75. It is triggered remotely when a user is induced to open a crafted HTML page, which causes a freed memory object in WebRTC to be reused and permits the attacker to run code in the renderer. Successful exploitation yields arbitrary code execution inside Chrome's sandbox, affecting the confidentiality, integrity, and availability of the browsing session, though it does not by itself escape the sandbox, which is why Google rates it Medium on the Chromium severity scale despite the high CVSS score of 8.8. Any user running an unpatched version of Google Chrome is affected. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days.
What to do: Update Google Chrome to version 152.0.7977.75 or later, verify the version in Settings > About Chrome, and push the update through enterprise browser management or patch tooling where applicable. Because exploitation requires user interaction with a crafted page, exercise caution with unsolicited links as an interim measure.
| Google Chrome | prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.