Junglewise Threat Intelligence

CVE-2026-14060: Google Chrome privilege escalation in Chromoting

CVE-2026-14060 · Severity: info · CVSS 2.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Chromoting (Remote Desktop) component of Google Chrome on Windows could allow a local user to gain elevated privileges. By using a specially crafted file, an attacker who already has basic access to a machine could perform actions with higher-level permissions than intended. This could lead to unauthorized system changes or access to restricted data on the affected workstation.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Chromoting component of Google Chrome for Windows. The flaw stems from insufficient validation of untrusted input when processing specific files. A local, authenticated attacker can exploit this by placing a malicious file on the system, leading to local privilege escalation (LPE). The vulnerability is rated as Low severity by Chromium. Users should update to version 150.0.7871.47 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats