Junglewise Threat Intelligence

CVE-2026-13830: Google Chrome use after free in Chromoting

CVE-2026-13830 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's Chromoting component, which is used for remote desktop capabilities. An attacker could exploit this flaw by sending specially crafted network traffic to a user's device. If successful, this could allow the attacker to take control of the affected system or execute unauthorized commands, potentially compromising sensitive data and system integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome for Linux. The flaw is triggered by the improper handling of memory during the processing of malicious network traffic. A remote, unauthenticated attacker can exploit this condition to achieve arbitrary code execution (RCE) within the context of the browser process. The vulnerability is tracked as CWE-416 and was addressed in Google Chrome version 150.0.7871.47. Access to specific bug details remains restricted to prevent further exploitation until a majority of users have updated.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-16: disclosed: Reported by Google internal researchers
  • 2026-06-30: patched: Fixed in version 150.0.7871.47 for Linux
  • 2026-06-30: advisory

References

Related threats