MEDIUM
CVE-2026-12461
CVSS
6.5
Description
Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Summary dbcve.org
An out-of-bounds read vulnerability exists in the WebRTC component of Google Chrome on Windows versions prior to 149.0.7827.155. A remote attacker can exploit this by tricking a user into visiting a crafted HTML page, allowing the attacker to read memory outside allocated buffers and potentially extract sensitive information from the process memory space.
Mitigation
Upgrade Google Chrome to version 149.0.7827.155 or later on all Windows systems. Apply browser updates through organizational patch management processes.
Weakness (CWE)
CWE-125
Out-of-bounds Read
EPSS Score
0.24%
Probability of exploitation in next 30 days
15.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.