Skip to main content
Vulnerability Database/CVE-2026-106268

CVE-2026-106268: Google Chrome WebRTC Use After Free Flaw

CVE-2026-106268 is a use after free vulnerability in Google Chrome WebRTC that enables remote attackers to execute arbitrary code within the sandbox through malicious web pages. This article covers technical details, affected versions, security impact, and recommended mitigation strategies.

Published:

CVE-2026-106268 Overview

CVE-2026-106268 is a use-after-free vulnerability [CWE-416] in the WebRTC component of Google Chrome. The flaw affects all Chrome desktop builds prior to 155.0.8059.39. A remote attacker can trigger the condition by convincing a user to load a crafted HTML page. Successful exploitation permits arbitrary code execution inside the Chrome renderer sandbox. Google classifies the Chromium security severity as High.

Critical Impact

Remote attackers can execute arbitrary code within the Chrome sandbox by delivering a malicious web page to any user running a vulnerable Chrome build.

Affected Products

  • Google Chrome Desktop (Windows, macOS, Linux) prior to 155.0.8059.39
  • Chromium-based browsers that embed the vulnerable WebRTC component
  • Applications integrating Chromium Embedded Framework (CEF) with pre-155 WebRTC code

Discovery Timeline

  • 2026-10-06 - CVE-2026-106268 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-106268

Vulnerability Analysis

The vulnerability resides in the Web Real-Time Communication (WebRTC) subsystem of Chrome. WebRTC handles peer-to-peer audio, video, and data channel streams directly inside the renderer process. A use-after-free condition occurs when the component continues to reference a memory region after the backing object has been freed. An attacker who controls the freed allocation can overwrite the dangling pointer with crafted data. This enables control of program flow and leads to arbitrary code execution inside the renderer sandbox.

Root Cause

The root cause is improper object lifetime management within WebRTC [CWE-416]. Reference tracking fails to prevent reuse of a freed object during specific stream negotiation or teardown sequences. Chromium's issue tracker entry 565742177 tracks the implementation details and the vendor fix.

Attack Vector

Exploitation requires network reachability and user interaction. The attacker hosts a crafted HTML page that initiates WebRTC APIs to drive the vulnerable code path. When the victim loads the page, the renderer processes attacker-supplied signaling or media negotiation data. The attack executes without authentication and relies only on the victim visiting an attacker-controlled or compromised site. Code executes inside the Chrome sandbox and typically requires chaining with a sandbox escape for full host compromise. See the Chromium Issue Tracker Entry for technical references.

Detection Methods for CVE-2026-106268

Indicators of Compromise

  • Chrome renderer processes crashing with heap corruption signatures while a WebRTC session is active.
  • Unexpected child processes spawned by chrome.exe after browsing untrusted sites with WebRTC content.
  • Outbound WebRTC signaling (stun:, turn:, DTLS/SRTP) to unknown infrastructure immediately before renderer instability.
  • Browser telemetry showing Chrome versions below 155.0.8059.39 still deployed on managed endpoints.

Detection Strategies

  • Inventory browser versions across the fleet and flag any Chrome build earlier than 155.0.8059.39.
  • Correlate renderer crash dumps with WebRTC module frames to identify likely exploitation attempts.
  • Monitor web proxy and DNS logs for suspicious domains serving pages that initiate unsolicited WebRTC peer connections.

Monitoring Recommendations

  • Enable browser crash reporting and ingest telemetry into a centralized data lake for correlation.
  • Track process lineage from Chrome renderer processes to detect post-exploitation child processes or injected code.
  • Alert on anomalous STUN/TURN traffic from endpoints that do not normally use real-time communications.

How to Mitigate CVE-2026-106268

Immediate Actions Required

  • Update Google Chrome to version 155.0.8059.39 or later on all Windows, macOS, and Linux endpoints.
  • Restart Chrome after the update to ensure the patched binaries are loaded by all renderer processes.
  • Audit Chromium-based browsers and embedded Chromium frameworks for the vulnerable WebRTC code and apply vendor updates.

Patch Information

Google released the fix in the Chrome Stable channel update at version 155.0.8059.39. Details are available in the Google Chrome Release Update. Chromium downstream maintainers should rebase affected branches onto the patched commit referenced in Chromium Issue 565742177.

Workarounds

  • Enforce automatic Chrome updates through enterprise policy to minimize patch latency.
  • Disable WebRTC in managed browser profiles where real-time communication is not required for business use.
  • Restrict user navigation to untrusted sites via web filtering until all endpoints are patched.
  • Apply strict Content Security Policy and site isolation controls to reduce renderer-side attack surface.
bash
# Verify installed Chrome version on Linux/macOS
google-chrome --version

# Windows: query installed version from registry
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version

# Enforce auto-update via Chrome Enterprise policy (Linux example)
cat > /etc/opt/chrome/policies/managed/update_policy.json <<EOF
{
  "AutoUpdateCheckPeriodMinutes": 60,
  "DefaultBrowserSettingEnabled": true
}
EOF

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.