PT-2026-42231 · Google+1 · Google Chrome+1
CVE-2026-9111
·
Published
2026-04-20
·
Updated
2026-08-31
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 148.0.7778.179
Description
A use-after-free flaw exists in WebRTC, the component powering in-browser video and voice calls. A use-after-free is a memory corruption issue that occurs when an application continues to use a pointer after it has been freed. This allows a remote attacker to execute arbitrary code on the system simply by enticing a user to load a specially crafted HTML page, without requiring any downloads or user interaction. Because WebRTC has direct access to the camera, microphone, and network, this flaw could lead to a full system takeover.
Recommendations
Update Google Chrome to version 148.0.7778.179 or later and restart the browser to apply the update.
Fix
RCE
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Red Os