Executive brief
A critical vulnerability has been identified in Google Chrome's Chromoting component, which is used for remote desktop capabilities. A remote attacker can exploit this flaw by sending malicious network traffic to a user's device, potentially allowing them to take full control of the system. This could lead to the theft of sensitive data, installation of malware, or complete disruption of business operations.
Technical details
A use-after-free (UAF) vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome. The flaw is triggered when the application continues to use a memory pointer after it has been freed, which can be induced by a remote attacker sending specially crafted network traffic. This vulnerability does not require user interaction or local authentication, making it highly dangerous. Successful exploitation allows for remote code execution (RCE) within the context of the browser or the underlying system. Google has addressed this issue in Chrome version 149.0.7827.53.
Affected products
- Google Chrome Prior to 149.0.7827.53
Timeline
- 2026-05-14: disclosed: Reported by Google internal researchers
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
- 2026-06-04: advisory: NVD publication date