Junglewise Threat Intelligence

CVE-2026-78892: Google Chrome Chromoting incorrect authorization on Windows

CVE-2026-78892 · Severity: high · CVSS 7.1 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's Chromoting remote access feature on Windows contains an authorization flaw that allows a local attacker to bypass system access restrictions. An attacker with local program execution capabilities could exploit this to gain elevated access to the system without proper authorization checks.

Technical details

This is an incorrect authorization vulnerability in the Chromoting component of Google Chrome on Windows. The vulnerability stems from improper authorization checks in the Chromoting access control logic, allowing a local attacker to circumvent system access restrictions via a local program. The attack requires local code execution capability on the affected system. The vulnerability was patched in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux).

Affected products

  • Google Chrome prior to 152.0.7977.65 on Windows

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats