Junglewise Threat Intelligence

CVE-2026-78913: Google Chrome use-after-free in Chromoting

CVE-2026-78913 · Severity: high · CVSS 8.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Chromoting remote access feature contains a memory management vulnerability that allows attackers to execute arbitrary code outside the browser's security sandbox. An attacker can exploit this flaw by sending specially crafted network traffic to a user running a vulnerable Chrome version, potentially gaining full control over the user's system.

Technical details

A use-after-free vulnerability exists in Chrome's Chromoting component (remote access feature) in versions prior to 152.0.7977.65. The vulnerability is triggered via crafted network traffic and allows code execution outside the browser sandbox, indicating a severe memory safety flaw in the Chromoting implementation. The attack vector is network-based and requires the Chromoting service to be active or accessible; successful exploitation grants an attacker code execution at the privilege level of the Chrome process. The vulnerability was patched in Chrome 152.0.7977.65, released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed

References

Related threats