Executive brief
A vulnerability exists in Google Chrome's Chromoting component, which is used for remote desktop capabilities. A remote attacker could exploit this flaw by sending specially crafted network traffic to a user's device. If successful, this could allow the attacker to take control of the system or execute unauthorized commands, potentially compromising sensitive data or disrupting operations.
Technical details
A use-after-free (UAF) vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome. The flaw is triggered when the application attempts to access memory that has already been freed, specifically during the processing of malicious network traffic. A remote, unauthenticated attacker can exploit this by sending crafted network packets to a target system, leading to memory corruption. This can result in arbitrary code execution within the context of the browser process. The vulnerability is addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update.
- 2026-06-04: disclosed: CVE published to NVD.