Junglewise Threat Intelligence

CVE-2026-11170: Google Chrome Chromoting privilege escalation on Linux

CVE-2026-11170 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Chromoting (Remote Desktop) component of Google Chrome on Linux could allow a remote attacker to gain elevated system-level privileges. By sending specially crafted network traffic, an attacker could bypass security boundaries to execute commands with higher authority than the browser normally allows. This could lead to a full compromise of the affected Linux workstation or server.

Technical details

A privilege escalation vulnerability exists in the Chromoting (Chrome Remote Desktop) implementation within Google Chrome for Linux. The flaw is characterized as an 'inappropriate implementation' that can be triggered by a remote attacker via malicious network traffic. Successful exploitation allows the attacker to escalate their privileges to the operating system level, potentially gaining full control over the host environment. The vulnerability was addressed in Chrome version 149.0.7827.53. While specific root cause details are restricted, the attack vector involves network-based interaction with the Chromoting service.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released for Linux
  • 2026-06-04: disclosed: CVE-2026-11170 published

References

Related threats