ZeroHour

CVE-2026-84347

mass

Use-after-free in Google Chrome WebRTC allows sandboxed code execution

CVSS 3.1
8.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-84347 is a use-after-free vulnerability (CWE-416) in the WebRTC component of Google Chrome that affects all releases prior to 152.0.7977.75. It is triggered remotely when a user is induced to open a crafted HTML page, which causes a freed memory object in WebRTC to be reused and permits the attacker to run code in the renderer. Successful exploitation yields arbitrary code execution inside Chrome's sandbox, affecting the confidentiality, integrity, and availability of the browsing session, though it does not by itself escape the sandbox, which is why Google rates it Medium on the Chromium severity scale despite the high CVSS score of 8.8. Any user running an unpatched version of Google Chrome is affected. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Update Google Chrome to version 152.0.7977.75 or later, verify the version in Settings > About Chrome, and push the update through enterprise browser management or patch tooling where applicable. Because exploitation requires user interaction with a crafted page, exercise caution with unsolicited links as an interim measure.

Affected
Google Chromeprior to 152.0.7977.75
Estimated exposure
mass≈3 billion+ users (Chrome holds roughly two-thirds of global browser market share) — Chrome is the world's most widely used browser with an estimated ~65% market share, implying on the order of several billion users, though the number actually vulnerable at any moment depends on patch uptake of the 152.0.7977.75 release.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.