Executive brief
A critical vulnerability exists in Google Chrome's Chromoting (Remote Desktop) component on macOS. This flaw could allow a remote attacker to execute malicious code on a user's computer by sending specially crafted network traffic. Successful exploitation could lead to full system compromise, unauthorized data access, or the installation of malware.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the Chromoting component of Google Chrome for macOS. The flaw is triggered by processing malicious network traffic, which can lead to memory corruption and arbitrary code execution in the context of the browser process. The vulnerability was reported by Google internally and is addressed in Chrome version 149.0.7827.53. Attackers can exploit this over the network without requiring local access, though specific preconditions regarding the state of the Chromoting session may apply.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-22: disclosed: Reported by Google researchers
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53/54
- 2026-06-04: advisory: NVD publication date