Junglewise Threat Intelligence

CVE-2026-11224: Google Chrome use after free in Chromoting

CVE-2026-11224 · Severity: info · CVSS 0 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Chromoting (remote desktop) component of Google Chrome for Linux. An attacker could potentially exploit this flaw to execute unauthorized code on a user's system by sending specially crafted network traffic. This could lead to a complete compromise of the affected machine, though the vendor has categorized the severity as low.

Technical details

A use-after-free (UAF) vulnerability exists in the Chromoting component of Google Chrome for Linux. The flaw is triggered by the processing of malicious network traffic, which can lead to memory corruption and potentially arbitrary code execution (ACE). The vulnerability is classified under CWE-416. While the impact of ACE is typically high, Chromium has assigned this a 'Low' security severity rating. The issue is resolved in Google Chrome version 149.0.7827.53 for Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Stable channel update released for desktop
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats