Junglewise Threat Intelligence

CVE-2026-84334: Google Chrome incorrect authorization in Chromoting

CVE-2026-84334 · Severity: high · CVSS 8.1 · Published 2026-09-02

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's Chromoting remote access feature on Windows contains an authorization flaw that allows a local attacker to execute arbitrary code outside the browser sandbox. An attacker with access to the local system can bypass security protections and run malicious code with elevated privileges, potentially compromising the entire system.

Technical details

An incorrect authorization vulnerability exists in the Chromoting component of Google Chrome on Windows versions prior to 152.0.7977.75. The vulnerability allows a local attacker to bypass sandbox restrictions and execute arbitrary code outside the sandbox context via a local program. This is a privilege escalation issue where the authorization checks are insufficient, enabling a locally authenticated attacker to escalate privileges and achieve code execution with reduced sandbox constraints. The vulnerability was patched in Chrome 152.0.7977.75 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.75 on Windows

Timeline

  • 2026-09-02: disclosed

References

Related threats