
Chromium security finding I reported earlier this year has now been assigned CVE-2026-78950. The issue was in WebRTC’s "RTCRtpSender.setParameters()" path, where a WebIDL "unsigned long" "maxBitrate" could cross into a signed C++ "int", creating an unsafe unsigned→signed conversion. What made this especially interesting: the same conversion risk had already been flagged during Chromium code review back in 2018, but the requested guard was never landed. The finding showed how a seemingly small WebIDL/native type mismatch can persist for years inside a major browser codebase and eventually surface as a security issue. Always interesting to trace a bug from a weird API edge case, through the native implementation and historical code review, all the way to an official CVE.
Post summary
The text announces CVE-2026-78950, a type conversion flaw in Chromium’s WebRTC implementation, detailing the technical nature of the issue without mentioning attacks, patches, or PoC code.
