Executive brief
Google Chrome is a widely-used web browser that includes a Chromoting feature for remote desktop access. A use-after-free vulnerability in Chromoting allows a remote attacker to execute arbitrary code outside the browser's sandbox by sending specially crafted network traffic, potentially compromising user systems and accessing sensitive data.
Technical details
A use-after-free vulnerability exists in the Chromoting component of Google Chrome on Windows prior to version 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. Use-after-free bugs occur when memory is accessed after it has been freed, potentially allowing an attacker to control program execution. The attack vector is network-based and does not require user authentication or interaction beyond receiving the malicious network traffic. The fix was included in Chrome 152.0.7977.65 (Windows) and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65 (Windows)
Timeline
- 2026-08-25: disclosed: CVE-2026-79194 disclosed in Chrome 152 stable release
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows