Executive brief
Google Chrome's Chromoting (remote desktop) component contains a memory access vulnerability that allows a local attacker to read data outside the security sandbox on Windows systems. An attacker with local access to a machine running affected Chrome versions can exploit this flaw to access sensitive information stored in memory, potentially bypassing Chrome's security isolation mechanisms.
Technical details
The vulnerability is an out-of-bounds read in the Chromoting component of Google Chrome on Windows. An attacker with local access to a system can craft a malicious local program that triggers an out-of-bounds memory read in the Chromoting service, allowing unauthorized access to memory regions outside the Chrome sandbox. The flaw requires local code execution capability on the target machine. Google fixed this issue in Chrome 153.0.8010.36 released on September 8, 2026, and classified it as High severity within the Chromium project despite the assigned CVSS score of 2.7.
Affected products
- Google Chrome prior to 153.0.8010.36 on Windows
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36