Junglewise Threat Intelligence

CVE-2026-11281: Google Chrome integer overflow in Chromoting

CVE-2026-11281 · Severity: info · CVSS 2 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Chromoting (Remote Desktop) component of Google Chrome on Windows could allow a local user to access sensitive information. By using a specially crafted system event, an attacker could read data from the browser's memory that they should not have access to. This could potentially expose private user data or internal process information.

Technical details

An integer overflow vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome for Windows. The flaw is triggered when processing specially crafted Event Tracing for Windows (ETW) events. A local attacker can exploit this condition to cause an out-of-bounds memory access, leading to the disclosure of potentially sensitive information from the process memory. The vulnerability is assigned a 'Low' severity by Chromium and is addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
  • 2026-06-05: disclosed: CVE published.

References

Related threats