Executive brief
A security vulnerability exists in Google Chrome's Chromoting (Remote Desktop) feature. This component allows users to remotely access and control their computers through the browser. A remote attacker could exploit this flaw to execute unauthorized code on a user's system, potentially leading to full system compromise or data theft.
Technical details
A use-after-free vulnerability (CWE-416) exists in the Chromoting component of Google Chrome. The flaw is triggered by processing malicious network traffic, allowing a remote attacker to potentially execute arbitrary code in the context of the browser process. While the attack vector is network-based and requires no prior privileges, it is characterized by high attack complexity. The vulnerability was addressed in Google Chrome version 147.0.7727.138 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-04-11: disclosed: Reported by Google internal researchers
- 2026-04-28: patched: Fixed in Stable Channel Update 147.0.7727.138
- 2026-04-28: advisory