Junglewise Threat Intelligence

CVE-2026-8586: Google Chrome DAC bypass in Chromoting

CVE-2026-8586 · Severity: medium · CVSS 5.5 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security flaw was identified in Chromoting, the remote desktop component of Google Chrome. This vulnerability could allow a person with local access to a computer to bypass security restrictions and access files or data they should not be able to see. This could lead to unauthorized access to sensitive information on the affected device.

Technical details

An inappropriate implementation vulnerability exists in the Chromoting (Chrome Remote Desktop) component of Google Chrome. The flaw is triggered by the handling of malicious files, which allows a local attacker to bypass Discretionary Access Control (DAC) mechanisms. By exploiting this, an attacker with local access to the system can gain unauthorized access to restricted resources or data. The issue is resolved in Google Chrome version 148.0.7778.168 for Windows and Mac, and 148.0.7778.167 for Linux.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-05-12: patched: Stable channel update released for desktop.
  • 2026-05-14: disclosed: NVD publication date.

References

Related threats