Junglewise Threat Intelligence

CVE-2026-13779: Google ChromeOS use after free in Chromoting

CVE-2026-13779 · Severity: info · CVSS 10 · Published 2026-06-30

Technologies: Google ChromeOS. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in the Chromoting (Remote Desktop) component of Google ChromeOS. This component allows users to access their computers remotely over a network. An attacker could exploit this flaw to take complete control of an affected device, potentially leading to the theft of sensitive data or the disruption of business operations.

Technical details

A use-after-free (UAF) vulnerability exists in the Chromoting component of Google ChromeOS prior to version 150.0.7871.47. The flaw is triggered when the system incorrectly manages memory during the processing of network traffic, allowing a remote, unauthenticated attacker to execute arbitrary code with the privileges of the browser process. This is classified as a Critical severity issue by the Chromium project (CWE-416). Users are advised to update to ChromeOS version 150.0.7871.47 or later to mitigate this risk.

Affected products

  • Google ChromeOS prior to 150.0.7871.47

Timeline

  • 2026-05-14: disclosed: Reported to Google internally
  • 2026-06-30: patched: Fixed in version 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats