CVE-2026-87430
massBuffer Overflow in Google Chrome WebRTC Allows Sandboxed Code Execution
CVE-2026-87430 is a buffer overflow (tracked as CWE-122, heap-based buffer overflow) in the WebRTC component of Google Chrome, fixed in version 153.0.8010.36. A remote attacker triggers it by convincing a user to open a crafted HTML page (the CVSS vector requires user interaction and no privileges), corrupting memory in the WebRTC code. Successful exploitation potentially allows arbitrary code execution, but only inside Chrome's browser sandbox, limiting the attacker to the sandboxed process context rather than full system compromise. All users running Google Chrome prior to 153.0.8010.36 are affected. There is currently no known exploitation: Chromium rates the flaw Low, EPSS assigns a 0.4% 30-day exploitation probability, it is not in CISA's KEV catalog, and no public proof-of-concept exists.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify the running version at chrome://version; for managed fleets, confirm auto-update behavior through Chrome Browser Cloud Management or your endpoint management tool. Because any visited website can reach the WebRTC code and no practical workaround exists, treat browser patching as routine hygiene, noting that the sandbox limits impact and there are no signs of active exploitation.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer overflow in WebRTC in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
- Vendors
- Products
- chrome
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.