Junglewise Threat Intelligence

CVE-2026-14084: Google Chrome heap corruption in Chromoting

CVE-2026-14084 · Severity: info · CVSS 3.1 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's remote desktop feature, Chromoting, contains a vulnerability that could allow a remote attacker to cause memory corruption. This occurs when the software fails to properly check data received over the network. While the risk is considered low, an exploit could potentially lead to application instability or crashes during remote desktop sessions.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome. The flaw is triggered by insufficient validation of untrusted input received via network traffic, which can lead to heap corruption. A remote attacker can exploit this by sending specially crafted network packets to a system running an affected version of Chrome. While the Chromium project classifies the severity as Low, heap corruption typically impacts process stability and could potentially be leveraged for further exploitation. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats