Junglewise Threat Intelligence

CVE-2026-76017: Google Chrome use-after-free in Chromoting

CVE-2026-76017 · Severity: high · CVSS 8.8 · Published 2026-08-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's remote desktop feature (Chromoting) contains a use-after-free memory vulnerability that allows an attacker to execute arbitrary code outside the browser's security sandbox. An attacker could exploit this via specially crafted network traffic to gain full control over an affected system and bypass Chrome's protective isolation mechanisms.

Technical details

A use-after-free vulnerability exists in the Chromoting component of Google Chrome versions prior to 151.0.7922.173. The vulnerability arises from improper memory management where a freed object is accessed after deallocation. Attack vectors include crafted network traffic sent to a Chromoting endpoint, requiring network connectivity but no authentication. Successful exploitation allows an attacker to execute arbitrary code with privileges outside the Chrome sandbox, potentially enabling full system compromise. The vulnerability is patched in Chrome 151.0.7922.173 and later versions.

Affected products

  • Google Chrome prior to 151.0.7922.173

Timeline

  • 2026-08-20: disclosed
  • 2026-08-20: patched: Fixed in Chrome 151.0.7922.173

References

Related threats