Executive brief
A vulnerability exists in the Chromoting (Remote Desktop) component of Google Chrome for Linux. This flaw could allow a remote attacker to execute unauthorized code on a user's system if the user interacts with malicious network traffic. While the potential impact includes arbitrary code execution, the vendor has classified this specific issue as low severity.
Technical details
A use-after-free (UAF) vulnerability exists in the Chromoting component of Google Chrome for Linux prior to version 150.0.7871.47. The flaw is triggered when the application attempts to use memory after it has been freed, specifically during the processing of malicious network traffic. A remote attacker can exploit this to achieve arbitrary code execution in the context of the browser process. Although UAF bugs are often critical, Chromium security has rated this specific instance as Low severity. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched