Description
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in the Chromoting component of Google Chrome on Linux before version 150.0. crafted network traffic that targets the Chromoting service, an attacker can trigger access to freed memory, leading to arbitrary code execution. The weakness is identified as CWE‑416, indicating improper handling of memory after deallocation, and grants the attacker full control over the compromised host.

Affected Systems

Google Chrome installations on Linux distributions using any version prior to 150.0.7871.47 are impacted. The flaw is specific to the Chromoting protocol support in these builds, and only Linux configurations of Chrome are affected.

Risk and Exploitability

The CVSS score is 8.8, indicating high severity. The EPSS score is less than 1%, suggesting a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly known exploits have been observed. The likely attack vector is remote network traffic that engages Chrome’s Chromoting service; an attacker must be able to send crafted packets to the target host for successful exploitation.

Generated by OpenCVE AI on July 17, 2026 at 14:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later on all Linux systems.
  • Disable or restrict the Chromoting feature via Chrome policies or settings to prevent remote‑desktop connections.
  • Implement network controls or monitoring to detect and block suspicious traffic targeting Chrome’s Chromoting service.

Generated by OpenCVE AI on July 17, 2026 at 14:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Chromoting Enables Remote Code Execution on Linux

Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Chromoting Enables Remote Code Execution on Linux

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Chromoting Enables Remote Code Execution on Linux

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Chromoting Enables Remote Code Execution on Linux

Sat, 11 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free in Google Chrome for Linux Enables Remote Code Execution

Fri, 10 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free in Google Chrome for Linux Enables Remote Code Execution

Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chromoting Enables Remote Code Execution on Linux Chrome

Thu, 09 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chromoting Enables Remote Code Execution on Linux Chrome

Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Chromoting Allows Remote Code Execution on Linux

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Chromoting Allows Remote Code Execution on Linux

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Chromoting on Linux allows Remote Code Execution

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Chromoting on Linux allows Remote Code Execution

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free in Chrome on Linux Enables Remote Code Execution

Sat, 04 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free in Chrome on Linux Enables Remote Code Execution

Sat, 04 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Chromoting Use-After-Free in Google Chrome on Linux Enables Remote Code Execution

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Chromoting Use-After-Free in Google Chrome on Linux Enables Remote Code Execution

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free Enables Remote Code Execution on Linux Chrome

Thu, 02 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free Enables Remote Code Execution on Linux Chrome

Thu, 02 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free Vulnerability Exposing Remote Code Execution in Google Chrome on Linux

Thu, 02 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free Vulnerability Exposing Remote Code Execution in Google Chrome on Linux

Thu, 02 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Chromoting on Linux Enables Remote Code Execution

Wed, 01 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Chromoting on Linux Enables Remote Code Execution

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free Enables Remote Code Execution in Google Chrome on Linux

Wed, 01 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chromoting Use‑After‑Free Enables Remote Code Execution in Google Chrome on Linux

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:55:39.612Z

Reserved: 2026-06-29T23:03:28.216Z

Link: CVE-2026-13830

cve-icon Vulnrichment

Updated: 2026-07-01T13:29:28.187Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:00:10Z

Weaknesses