Junglewise Threat Intelligence

CVE-2026-17877: Google Chrome Chromoting privilege escalation on Linux

CVE-2026-17877 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Chromoting (Remote Desktop) component of Google Chrome on Linux could allow a local user to gain elevated system privileges. By sending specially crafted network traffic, an attacker who already has limited access to the machine could take full control of the operating system. This could lead to unauthorized access to sensitive data, installation of malicious software, or disruption of system operations.

Technical details

An inappropriate implementation vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome on Linux. The flaw allows a local attacker to escalate their privileges to the OS level by generating malicious network traffic targeted at the vulnerable component. The vulnerability is present in versions prior to 151.0.7922.72. While the attack vector involves network traffic, the advisory classifies the attacker as local, suggesting the traffic must originate from the local host or a specific local network context to trigger the privilege escalation. Google has addressed this issue in the stable channel update 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.71 for Linux.
  • 2026-07-30: disclosed: NVD publication date.

References

Related threats