Junglewise Threat Intelligence

CVE-2026-10978: Google Chrome use after free in Chromoting

CVE-2026-10978 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's Chromoting (Remote Desktop) feature on Windows. This flaw could allow a remote attacker to execute unauthorized code on a user's computer if they encounter specially crafted network traffic. Such an exploit could lead to a complete system compromise, allowing attackers to steal sensitive data or disrupt business operations.

Technical details

A use-after-free (UAF) vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome on Windows. The flaw is triggered when the application attempts to use memory that has already been deallocated during the processing of network traffic. A remote attacker can exploit this by sending specially crafted network packets to a target system, potentially leading to arbitrary code execution (ACE) within the context of the browser process. The vulnerability is addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE-2026-10978 published

References

Related threats