Junglewise Threat Intelligence

CVE-2026-79194: Google Chrome use after free in Chromoting

CVE-2026-79194 · Severity: high · CVSS 8.1 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome is a widely-used web browser that includes a Chromoting feature for remote desktop access. A use-after-free vulnerability in Chromoting allows a remote attacker to execute arbitrary code outside the browser's sandbox by sending specially crafted network traffic, potentially compromising user systems and accessing sensitive data.

Technical details

A use-after-free vulnerability exists in the Chromoting component of Google Chrome on Windows prior to version 152.0.7977.65. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. Use-after-free bugs occur when memory is accessed after it has been freed, potentially allowing an attacker to control program execution. The attack vector is network-based and does not require user authentication or interaction beyond receiving the malicious network traffic. The fix was included in Chrome 152.0.7977.65 (Windows) and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65 (Windows)

Timeline

  • 2026-08-25: disclosed: CVE-2026-79194 disclosed in Chrome 152 stable release
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows

References

Related threats