Description
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Published: 2026-06-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the Chromoting component of Google Chrome on Windows permits a local attacker to invoke code execution with elevated privileges through a malicious file. The bug allows the attacker to abuse freed memory, potentially overriding function pointers or control flow to run arbitrary OS‑level code, which can lead to full system compromise if the user has higher privileges than the attacker.

Affected Systems

Google Chrome versions on Windows released before build 149.0.7827.155 are affected. Users running these builds on any Windows operating system are at risk until they install the updated Chrome rev.

Risk and Exploitability

The CVSS v3.1 score of 7.8 reflects the high impact of privilege escalation possible with local execution, yet the EPSS rate of less than 1% indicates that real‑world exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly known exploits. Attackers would need local access and to launch a crafted malicious file that Chrome processes, implying an insider or compromised user session. Until the update is applied, the risk remains medium to high for environments where users may open untrusted files from unverified sources.

Generated by OpenCVE AI on June 17, 2026 at 17:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome release that addresses this issue (build 149.0.7827.155 or newer).
  • Ensure Windows is fully patched with the latest security updates to limit privilege escalation.
  • Avoid opening unknown or malicious files on your system, especially those that might be processed by Chrome.

Generated by OpenCVE AI on June 17, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 17 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-17T13:01:46.490Z

Reserved: 2026-06-16T19:38:27.534Z

Link: CVE-2026-12449

cve-icon Vulnrichment

Updated: 2026-06-17T13:01:40.943Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T06:30:03Z

Weaknesses