Executive brief
A security vulnerability exists in the Chromoting (Remote Desktop) component of Google Chrome for Windows. This flaw could allow a local attacker to access sensitive information stored in the computer's memory by tricking a user into opening a specially crafted file. Such an exploit could lead to the exposure of private data or credentials from other active processes on the system.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Chromoting component of Google Chrome for Windows. The flaw is triggered when the application processes a malicious file, leading to memory access beyond the intended buffer. A local attacker can exploit this to read sensitive information from the process memory. The attack requires user interaction to open the malicious file. Google has addressed this issue in Chrome version 149.0.7827.155.
Affected products
- Google Chrome prior to 149.0.7827.155
Timeline
- 2026-05-14: disclosed: Reported to Google by internal researchers
- 2026-06-16: patched: Stable channel update released for desktop
- 2026-06-17: advisory: NVD entry published