Junglewise Threat Intelligence

CVE-2026-87525: Google Chrome out-of-bounds read in Chromoting on Windows

CVE-2026-87525 · Severity: low · CVSS 2.7 · Published 2026-09-09

Executive brief

Google Chrome's Chromoting (remote desktop) component contains a memory access vulnerability that allows a local attacker to read data outside the security sandbox on Windows systems. An attacker with local access to a machine running affected Chrome versions can exploit this flaw to access sensitive information stored in memory, potentially bypassing Chrome's security isolation mechanisms.

Technical details

The vulnerability is an out-of-bounds read in the Chromoting component of Google Chrome on Windows. An attacker with local access to a system can craft a malicious local program that triggers an out-of-bounds memory read in the Chromoting service, allowing unauthorized access to memory regions outside the Chrome sandbox. The flaw requires local code execution capability on the target machine. Google fixed this issue in Chrome 153.0.8010.36 released on September 8, 2026, and classified it as High severity within the Chromium project despite the assigned CVSS score of 2.7.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Windows

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36

References

Related threats