Executive brief
Google Chrome's Chromoting remote access feature on Windows contains an authorization flaw that allows a local attacker to bypass system access restrictions. An attacker with local program execution capabilities could exploit this to gain elevated access to the system without proper authorization checks.
Technical details
This is an incorrect authorization vulnerability in the Chromoting component of Google Chrome on Windows. The vulnerability stems from improper authorization checks in the Chromoting access control logic, allowing a local attacker to circumvent system access restrictions via a local program. The attack requires local code execution capability on the affected system. The vulnerability was patched in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux).
Affected products
- Google Chrome prior to 152.0.7977.65 on Windows
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)