Description
Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Sensitive Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing authorization check in the Chromoting component of Google Chrome for Windows. A remote attacker who can send specially crafted network traffic can bypass the expected access controls and capture sensitive information that is normally protected during a Chromoting session. The flaw falls under CWE‑862 and is classified as a medium‑severity issue by Chromium security.

Affected Systems

This issue affects Google Chrome versions prior to 155.0.8059.39 on Windows operating systems. Users who run older builds of Chrome and have Chromoting enabled are potentially vulnerable. All other platforms and newer Chrome releases are not impacted.

Risk and Exploitability

The vulnerability can be exploited from the network if the attacker can reach the Chromoting service. No EPSS score is publicly available and the issue is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation at this time. Despite that, the ability to obtain private session data may provide an attacker with valuable credentials or content. Because the flaw is remotely exploitable without local privileges, the risk remains significant.

Generated by OpenCVE AI on October 6, 2026 at 21:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or newer.
  • Disable or block Chromoting if it is not required, using group policy or firewall rules.
  • If Chromoting must remain active, isolate the service behind a segmented network and monitor for abnormal traffic patterns.

Generated by OpenCVE AI on October 6, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chromoting Authorization Bypass in Chrome on Windows Allows Sensitive Information Disclosure
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Missing authorization in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker to obtain sensitive information via crafted network traffic. (Chromium security severity: Medium)
Weaknesses CWE-862
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:39:04.263Z

Reserved: 2026-10-06T16:30:04.699Z

Link: CVE-2026-106183

cve-icon Vulnrichment

Updated: 2026-10-06T20:38:57.909Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:44.277

Modified: 2026-10-06T21:17:05.350

Link: CVE-2026-106183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:15:06Z

Weaknesses