Junglewise Threat Intelligence

CVE-2026-79247: Google Chrome use-after-free in Chromoting

CVE-2026-79247 · Severity: high · CVSS 8.3 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's remote desktop component (Chromoting) contains a use-after-free vulnerability that allows an attacker who has already compromised the browser's rendering engine to execute arbitrary code outside the security sandbox. This could enable unauthorized access to the user's system and data, bypassing Chrome's security protections.

Technical details

The vulnerability is a use-after-free memory safety issue in Chrome's Chromoting (remote desktop) component. An attacker who has already compromised the renderer process can exploit this flaw by sending crafted network traffic to execute arbitrary code outside the sandbox. The vulnerability requires prior renderer process compromise as a precondition. The fix is available in Chrome version 152.0.7977.65 and later for Windows, Mac, and Linux platforms.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released for Windows/Mac; 152.0.7977.64 for Linux

References

Related threats