
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12461 is an out-of-bounds read vulnerability in the WebRTC component of Google Chrome on Windows that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. It affects all Google Chrome versions prior to 149.0.7827.155 on Windows. The vulnerability was reported to Google on 2026-05-29 and patched on 2026-06-16 as part of a 33-fix stable channel update. It carries a CVSS v3.1 base score of 6.5 (Medium) and is rated High severity by Chromium's internal security classification (Chrome Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's WebRTC implementation on Windows. An attacker can exploit this by hosting a crafted HTML page that, when visited by a victim using a vulnerable Chrome version, triggers an out-of-bounds memory read within the WebRTC subsystem. Exploitation requires user interaction — specifically, a victim must navigate to an attacker-controlled or compromised web page — but no authentication or special privileges are required on the attacker's side. The Chromium bug tracker references issue 517727318 for this vulnerability, though full technical details remain restricted pending broad user adoption of the patch (Chrome Advisory).
Successful exploitation results in a memory disclosure attack, where the attacker can read potentially sensitive data from the Chrome process memory, including credentials, session tokens, or other in-memory content. The impact is limited to confidentiality — integrity and availability are not affected by this vulnerability. The scope is confined to the Chrome renderer process on Windows systems running unpatched versions, and there is no direct path to code execution from this vulnerability alone (Chrome Advisory, Red Hat Bugzilla).
Update Google Chrome to version 149.0.7827.155 or later on all Windows systems; the patch was released on June 16, 2026 as part of a stable channel update (Chrome Advisory). Microsoft Edge users should also apply the corresponding Edge update (149.0.4022.80 or later), which incorporates the same Chromium fixes. As a temporary workaround where immediate patching is not feasible, restrict user access to untrusted or unknown websites and consider disabling WebRTC via enterprise browser policy (WebRtcAllowed: false) to reduce attack surface. Organizations should use vulnerability scanners (Qualys, Nessus) to identify unpatched Chrome installations across their environment.
The June 2026 Chrome update, which included CVE-2026-12461 among 33 security fixes (7 rated Critical), received broad coverage from security media outlets including GBHackers, CyberSecurityNews, and CyberPress, with headlines emphasizing the critical memory safety flaws in the batch (GBHackers, CyberSecurityNews). The update was also noted in regional threat digests such as the HelpAG Middle East Cyber Threats report for June 23, 2026. Community reaction on platforms like Bluesky acknowledged the vulnerability, and downstream Linux distributions (Fedora, openSUSE, Debian) promptly issued Chromium package updates incorporating the fix.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."