Executive brief
A security vulnerability exists in Google Chrome's Chromoting (Remote Desktop) feature on Windows. This flaw could allow a local attacker to bypass the browser's security sandbox by using a specially crafted file. If exploited, an attacker could gain broader access to the underlying operating system, potentially leading to unauthorized data access or system compromise.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Chromoting component of Google Chrome for Windows. The flaw stems from insufficient validation of untrusted input when processing specific files. A local attacker can exploit this by providing a malicious file to the Chromoting service, potentially achieving a sandbox escape. This would allow code execution outside of the restricted browser environment on the host machine. The vulnerability is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched