Junglewise Threat Intelligence

CVE-2026-13787: Google Chrome use after free in Chromoting

CVE-2026-13787 · Severity: info · CVSS 10 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's remote desktop feature (Chromoting) on Windows. This flaw could allow a remote attacker to take control of a user's computer by sending specially crafted network traffic. If exploited, an attacker could execute unauthorized commands, access sensitive data, or disrupt business operations. Users should update to the latest version of Chrome immediately to mitigate this risk.

Technical details

A use-after-free (UAF) vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome for Windows. The flaw is triggered by the improper handling of memory objects during the processing of malicious network traffic. A remote, unauthenticated attacker can exploit this condition to achieve arbitrary code execution (RCE) within the context of the browser or the host system. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later. Google classifies this as a Critical severity issue.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-11: disclosed: Reported to Chromium by Google researchers
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47 for Windows
  • 2026-06-30: advisory

References

Related threats