Junglewise Threat Intelligence

CVE-2026-12449: Google Chrome use after free in Chromoting

CVE-2026-12449 · Severity: high · CVSS 7.8 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's remote desktop component (Chromoting) on Windows could allow a local attacker to gain elevated system privileges. By tricking a user into opening a specifically crafted malicious file, an attacker could bypass standard security restrictions to take control of the operating system. This could lead to unauthorized access to sensitive data or the ability to install persistent malware on the affected machine.

Technical details

A use-after-free (UAF) vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome for Windows. The flaw is triggered when the application incorrectly manages memory pointers after an object has been deleted, specifically when processing a malicious file. A local attacker can exploit this condition to execute arbitrary code with elevated system privileges. The attack requires user interaction to open the malicious file. Google has addressed this issue in Chrome version 149.0.7827.155.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-15: disclosed: Reported to Google by internal/external researchers.
  • 2026-06-16: patched: Stable channel update released.
  • 2026-06-17: advisory: NVD and Chrome security advisory published.

References

Related threats