Description
Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
Published: 2026-06-30
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the Chromoting component of Google Chrome on Windows allows a remote attacker to execute arbitrary code when Chrome receives specially crafted network traffic. The flaw falls under CWE‑416 and is assessed as Critical by Chromium. An attacker who can influence the network stream to the affected browser can trigger the exploit, leading to full compromise of the victim’s system.

Affected Systems

Google Chrome for Windows versions earlier than 150.0.7871.47 are affected. Systems running these versions without the latest update are vulnerable.

Risk and Exploitability

The vulnerability is remotely exploitable over the network. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. While a CVSS vector is not provided, the Critical severity and use‑after‑free nature suggest a high likelihood of exploitation if an attacker can reach the browser with malicious traffic. The exploit requires the Chromoting feature to be active, but does not impose additional user interaction or special privileges beyond the owning user of the Chrome process.

Generated by OpenCVE AI on July 1, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later
  • If Chromoting is not required, disable the feature in Chrome settings or via policy
  • Implement network filtering to block unsolicited traffic to the Chrome process

Generated by OpenCVE AI on July 1, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Chromoting Allows Remote Code Execution on Windows

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
Weaknesses CWE-416
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-30T22:37:32.782Z

Reserved: 2026-06-29T23:03:17.596Z

Link: CVE-2026-13787

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T01:15:16Z

Weaknesses