CVE-2026-78950Disclosure(google / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-25: 1Technical Details · 2026-08-25: 108-25
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Ashutosh Singh@0xAshutosh
    Disclosure

    Chromium security finding I reported earlier this year has now been assigned CVE-2026-78950. The issue was in WebRTC’s "RTCRtpSender.setParameters()" path, where a WebIDL "unsigned long" "maxBitrate" could cross into a signed C++ "int", creating an unsafe unsigned→signed conversion. What made this especially interesting: the same conversion risk had already been flagged during Chromium code review back in 2018, but the requested guard was never landed. The finding showed how a seemingly small WebIDL/native type mismatch can persist for years inside a major browser codebase and eventually surface as a security issue. Always interesting to trace a bug from a weird API edge case, through the native implementation and historical code review, all the way to an official CVE.

    Post summary

    The text announces CVE-2026-78950, a type conversion flaw in Chromium’s WebRTC implementation, detailing the technical nature of the issue without mentioning attacks, patches, or PoC code.

    00010333
    314 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more